[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kde-announce
Subject:    [kde-announce] KMail/KIO POP3 SSL MITM Flaw
From:       Richard Moore <rich () kde ! org>
Date:       2014-06-18 20:07:09
Message-ID: CAMp7mVsrRFx1mbpmgCTvSU7RFBA752DGwruQnX387q=dxFJtDA () mail ! gmail ! com
[Download RAW message or body]

[Attachment #2 (multipart/alternative)]


KDE Project Security Advisory
=============================

Title:          KMail/KIO POP3 SSL MITM Flaw
Risk Rating:    Medium
CVE:            CVE-2014-3494
Platforms:      All
Versions:       kdelibs 4.10.95 to 4.13.2
Author:         Richard J. Moore <rich@kde.org>
Date:           17 June 2014

Overview
========

The POP3 kioslave used by kmail will accept invalid certificates without
presenting a dialog to the user due a bug that leads to an inability to
display the dialog combined with an error in the way the result is checked.

Impact
======

This flaw allows an active attacker to perform MITM attacks against the
ioslave which could result in the leakage of sensitive data such as the
authentication details and the contents of emails.

Workaround
==========

None

Solution
========

Upgrade to version 4.13.3 or apply the patch at
http://quickgit.kde.org/?p=kdelibs.git&a=commitdiff&h=bbae87dc1be3ae063796a582774bd5642cacdd5d&hp=1ccdb43ed3b32a7798eec6d39bb3c83a6e40228f


Credits
=======

Thanks to Jim Scadden for reporting this issue and writing the initial fix,
and to David Faure for reviewing and improving the fix.


[Attachment #5 (text/html)]

<div dir="ltr"><div class="im" \
style="font-family:arial,sans-serif;font-size:13px">KDE Project Security \
Advisory<br>=============================<br><br>Title:          KMail/KIO POP3 SSL \
                MITM Flaw<br>Risk Rating:    Medium<br>
CVE:            CVE-2014-3494<br>Platforms:      All<br></div><span \
style="font-family:arial,sans-serif;font-size:13px">Versions:       kdelibs 4.10.95 \
to 4.13.2</span><br style="font-family:arial,sans-serif;font-size:13px"> <div \
class="im" style="font-family:arial,sans-serif;font-size:13px">Author:         \
Richard J. Moore &lt;<a href="mailto:rich@kde.org">rich@kde.org</a>&gt;<br>Date:      \
17 June 2014<br><br>Overview<br>========<br><br> The POP3 kioslave used by kmail will \
accept invalid certificates without<br>presenting a dialog to the user due a bug that \
leads to an inability to<br>display the dialog combined with an error in the way the \
result is checked.<br> <br>Impact<br>======<br><br>This flaw allows an active \
attacker to perform MITM attacks against the<br>ioslave which could result in the \
leakage of sensitive data such as the<br>authentication details and the contents of \
emails.<br> <br>Workaround<br>==========<br><br>None<br><br>Solution<br>========<br><br></div><span \
style="font-family:arial,sans-serif;font-size:13px">Upgrade to version 4.13.3 or \
apply the patch at</span><br style="font-family:arial,sans-serif;font-size:13px"> <a \
href="http://quickgit.kde.org/?p=kdelibs.git&amp;a=commitdiff&amp;h=bbae87dc1be3ae063796a582774bd5642cacdd5d&amp;hp=1ccdb43ed3b32a7798eec6d39bb3c83a6e40228f" \
target="_blank" style="font-family:arial,sans-serif;font-size:13px">http://quickgit.kd \
e.org/?p=kdelibs.git&amp;a=commitdiff&amp;h=bbae87dc1be3ae063796a582774bd5642cacdd5d&amp;hp=1ccdb43ed3b32a7798eec6d39bb3c83a6e40228f</a><br \
style="font-family:arial,sans-serif;font-size:13px"> <div class="im" \
style="font-family:arial,sans-serif;font-size:13px"><br>Credits<br>=======<br><br>Thanks \
to Jim Scadden for reporting this issue and writing the initial fix,<br></div><span \
style="font-family:arial,sans-serif;font-size:13px">and to David Faure for reviewing \
and improving the fix.</span><br> </div>



_______________________________________________
kde-announce mailing list
kde-announce@kde.org
https://mail.kde.org/mailman/listinfo/kde-announce


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic