Beveiligingsadvies

CVE-2024-34083

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-05-18 18:12:19
Laatst bijgewerkt 2024-08-02 02:42:59
Toegewezen door GitHub_M
CVSS-score 5.4
Status PUBLISHED

Beschrijving

aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a man-in-the-middle attack. Version 1.4.6 contains a patch for the issue.