Candidate: CVE-2019-8337 PublicDate: 2019-02-13 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8337 https://marlam.de/msmtp/news/ Description: In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=922345 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N [5.3 MEDIUM] Patches_msmtp: upstream_msmtp: needs-triage precise/esm_msmtp: DNE trusty_msmtp: ignored (reached end-of-life) trusty/esm_msmtp: DNE (trusty was needs-triage) xenial_msmtp: ignored (end of standard support, was needs-triage) bionic_msmtp: needs-triage cosmic_msmtp: ignored (reached end-of-life) disco_msmtp: not-affected (1.8.3-1) eoan_msmtp: not-affected (1.8.3-1) focal_msmtp: not-affected (1.8.3-1) groovy_msmtp: not-affected (1.8.3-1) hirsute_msmtp: not-affected (1.8.3-1) impish_msmtp: not-affected (1.8.3-1) jammy_msmtp: not-affected (1.8.3-1) devel_msmtp: not-affected (1.8.3-1) Patches_mpop: upstream_mpop: needs-triage precise/esm_mpop: DNE trusty_mpop: ignored (reached end-of-life) trusty/esm_mpop: DNE (trusty was needs-triage) xenial_mpop: not-affected (code not present) bionic_mpop: not-affected (code not present) cosmic_mpop: not-affected (code not present) disco_mpop: released (1.4.3-1) eoan_mpop: released (1.4.3-1) focal_mpop: released (1.4.3-1) groovy_mpop: released (1.4.3-1) hirsute_mpop: released (1.4.3-1) impish_mpop: released (1.4.3-1) jammy_mpop: released (1.4.3-1) devel_mpop: released (1.4.3-1)