CVE-2020-24661

NameCVE-2020-24661
DescriptionGNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the middle to present a different invalid certificate to intercept incoming and outgoing mail.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
geary (PTS)buster0.12.4-4vulnerable
bullseye3.38.1-1fixed
bookworm43.0-1fixed
sid, trixie44.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gearysource(unstable)3.38.0.1-1

Notes

[buster] - geary <no-dsa> (Minor issue)
[stretch] - geary <no-dsa> (Minor issue)
https://gitlab.gnome.org/GNOME/geary/-/issues/866
https://gitlab.gnome.org/GNOME/geary/commit/0d957559bbb4be81870c9fafba1c74f0926f59a3

Search for package or bug name: Reporting problems