CVE-2007-1137
putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows…
Does this matter?
Lower severity and a low EPSS score (0.89%). Track it; it rarely justifies an emergency change on its own.
Description
putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain sensitive information.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.89% probability · 57th percentile
- CISA KEV
- Not listed
- Affected
- sourceforge/putmail
- Source
- cve@mitre.org
References
- http://osvdb.org/33764
- http://putmail.sourceforge.net/home.html
- http://secunia.com/advisories/24266Vendor Advisory
- http://www.securityfocus.com/bid/22718
- http://www.vupen.com/english/advisories/2007/0753
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32689
- http://osvdb.org/33764
- http://putmail.sourceforge.net/home.html
- http://secunia.com/advisories/24266Vendor Advisory
- http://www.securityfocus.com/bid/22718
- http://www.vupen.com/english/advisories/2007/0753
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32689
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.