CVE-2020-37248

NameCVE-2020-37248
DescriptionOfflineIMAP before 8.0.3 trusts the server with their STARTTLS capabil ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1139329

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
offlineimap3 (PTS)bullseye0.0~git20210225.1e7ef9e+dfsg-4vulnerable
bookworm0.0~git20211018.e64c254+dfsg-2vulnerable
trixie0.0~git20240826.db34745+dfsg-2vulnerable
sid8.0.2+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
offlineimap3source(unstable)(unfixed)1139329

Notes

https://github.com/OfflineIMAP/offlineimap3/issues/222
https://github.com/OfflineIMAP/offlineimap/issues/669
Fixed by: https://github.com/OfflineIMAP/offlineimap3/commit/46505c53ef995455d66c685f9ec3ff6ea93dbb74 (v8.0.3)

Search for package or bug name: Reporting problems