CVE-2020-24661

Name
CVE-2020-24661
Description
GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the middle to present a different invalid certificate to intercept incoming and outgoing mail.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://gitlab.gnome.org/GNOME/geary/-/issues/866
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NS6CSTOBVO5HSAR3X5CT6DS6QDHXDB26/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G7OTYTGND6EFOKNQJWCHKKXKSN7SM73Y/
Broken Link https://tools.cisco.com/security/center/content/CiscoSeg/message/NS6CSTOBVO5HSAR3X5CT6DS6QDHXDB26/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnome:geary:*:*:*:*:*:*:*:* geary >= None < 3.36.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
geary edge-community 3.37.91-r0 None fixed
geary 3.22-community 3.37.91-r0 None fixed
geary 3.21-community 3.37.91-r0 None fixed
geary 3.20-community 3.37.91-r0 None fixed
geary 3.19-community 3.37.91-r0 None fixed
geary 3.18-community 3.37.91-r0 None fixed
geary 3.17-community 3.37.91-r0 None fixed