ZeroHour

CVE-2021-38373

CVSS 3.1
5.3 medium
EPSS
<1%p43
Published
()
Modified
Description

In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.

Vendors
kde
Products
kmail
Weakness
CWE-77, CWE-319
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.