Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Claws Mail 权限许可和访问控制漏洞
Vulnerability Description
Claws Mail是Claws Mail团队的一套基于GTK+开发的电子邮件客户端和阅读器程序。 Claws Mail 3.10.0之前版本的plugins/rssyl/feed.c脚本中存在安全漏洞,该漏洞源于程序对CN或SAN主机名字段禁用了CURLOPT_SSL_VERIFYHOST检查。远程攻击者可利用该漏洞欺骗服务器,实施中间人攻击。
CVSS Information
N/A
Vulnerability Type
N/A