FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2014-3494

This CVE name corresponds to:

Entered Topic
2014-07-16 kdelibs4 -- KMail/KIO POP3 SSL Man-in-the-middle Flaw

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2014-3494
Phase Assigned(20140514)

Description

kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows man-in-the-middle attackers to obtain sensitive information via an invalid certificate.

References

Source Reference
CONFIRM http://quickgit.kde.org/?p=kdelibs.git&a=commitdiff&h=bbae87dc1be3ae063796a582774bd5642cacdd5d&hp=1ccdb43ed3b32a7798eec6d39bb3c83a6e40228f
CONFIRM http://www.kde.org/info/security/advisory-20140618-1.txt
SUSE openSUSE-SU-2015:0573
BID 68113