VulnerabilityModified
CVE-2013-4584
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
MEDIUM 5.9EPSS 1.52%
Does this matter?
Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.
Description
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-755
- Affected
- horms/perdition · debian/debian linux
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2013/11/15/6Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/63696Third Party Advisory, VDB Entry
- https://access.redhat.com/security/cve/cve-2013-4584Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89184Third Party Advisory, VDB Entry
- https://github.com/horms/perdition/commit/62a0ce94aeb7dd99155882956ce9e327ab914ddfPatch
- https://security-tracker.debian.org/tracker/CVE-2013-4584Third Party Advisory
- http://www.openwall.com/lists/oss-security/2013/11/15/6Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/63696Third Party Advisory, VDB Entry
- https://access.redhat.com/security/cve/cve-2013-4584Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89184Third Party Advisory, VDB Entry
- https://github.com/horms/perdition/commit/62a0ce94aeb7dd99155882956ce9e327ab914ddfPatch
- https://security-tracker.debian.org/tracker/CVE-2013-4584Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.