CVE
- Id
- 69871
- CVE No.
- CVE-2014-2576
- Status
- Candidate
- Description
- plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
- Phase
- Assigned (20140321)
- Votes
- None (candidate not yet proposed)
- Comments