Computer Security
[EN] securityvulns.ru
no-pyccku



Mozilla Thunderbird / Mozilla weak authentication downgrade
Published:14.10.2005
Source:FULL-DISCLOSURE
SecurityVulns ID:5353
Type:m-i-t-m
Level:5/10
Description:If SMTP authentication with CRAM-MD5 or TLS hadshake fails mail agent downgrades to plain text authentication, allowing active man-in-the-middle attacks.
Affected:MOZILLA : Thunderbird 1.0
 MOZILLA : Thunderbird 1.5
Original documentdocumentThomas Henlich, [Full-disclosure] Mozilla Thunderbird SMTP down-negotiation weakness (14.10.2005)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server