ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-12398
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted con

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.

NVD description · AI analysis pending
7.5<1%
  • mozilla thunderbird
  • mozilla ubuntu linux
CVE-2020-14093
Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.

Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.

NVD description · AI analysis pending
5.92%
  • mutt mutt
  • mutt ubuntu linux
  • mutt debian linux
  • +1 more
CVE-2020-14928
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3.

evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."

NVD description · AI analysis pending
5.93% PoC
  • gnome evolution-data-server
  • gnome debian linux
  • gnome fedora
  • +1 more
CVE-2020-14929
Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behav

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.

NVD description · AI analysis pending
7.52%
  • alpine project alpine
  • alpine project fedora
  • alpine project debian linux
CVE-2020-14954
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3.

Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."

NVD description · AI analysis pending
5.92%
  • mutt mutt
  • mutt debian linux
  • mutt neomutt
  • +1 more
CVE-2020-15047
MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.

MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.

NVD description · AI analysis pending
5.9<1%
  • trojita project trojita
CVE-2020-15685
During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session.

During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7.

NVD description · AI analysis pending
8.8<1% PoC
  • mozilla thunderbird
CVE-2020-15917
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.

common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.

NVD description · AI analysis pending
9.83%
  • claws-mail claws-mail
  • claws-mail fedora
  • claws-mail backports sle
  • +1 more
CVE-2020-15953
LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3.

LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."

NVD description · AI analysis pending
7.42% PoC
  • libetpan project libetpan
  • libetpan project mailcore2
  • libetpan project fedora
  • +1 more
CVE-2020-15954
KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.

KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.

NVD description · AI analysis pending
6.5<1%
  • kde kmail
  • kde debian linux
CVE-2020-15955
In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail.

In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker.

NVD description · AI analysis pending
5.9<1%
  • fehcom s\/qmail
CVE-2020-16117
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal

In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.

NVD description · AI analysis pending
5.92% PoC
  • gnome evolution-data-server
  • gnome debian linux
CVE-2020-16118
In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH respo

In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.

NVD description · AI analysis pending
7.52% PoC
  • gnome balsa
  • gnome backports sle
  • gnome leap
CVE-2020-24661
GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificat

GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the middle to present a different invalid certificate to intercept incoming and outgoing mail.

NVD description · AI analysis pending
5.9<1% PoC
  • gnome geary
  • gnome fedora
CVE-2020-9941
This issue was addressed with improved checks.

This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. A remote attacker may be able to unexpectedly alter application state.

NVD description · AI analysis pending
7.53%
  • apple ipados
  • apple iphone os
  • apple mac os x
  • +1 more
CVE-2021-29969
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS han

If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders that didn't exist on the IMAP server. This vulnerability affects Thunderbird < 78.12.

NVD description · AI analysis pending
5.91%
  • mozilla thunderbird
CVE-2021-30696
An attacker in a privileged network position may be able to misrepresent application state.

An attacker in a privileged network position may be able to misrepresent application state. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A logic issue was addressed with improved state management.

NVD description · AI analysis pending
5.91%
  • apple mac os x
  • apple macos
Full article1,275 words · extracted from therecord.media · click to collapse

A group of German academics said they discovered more than 40 security flaws in the implementation of the STARTTLS feature in today's most popular email clients and email servers.

Also known as Opportunistic TLSSTARTTLS refers to a set of protocol extensions used by email clients and servers to upgrade older email protocols like POP3, IMAP, and SMTP from sending data via a plaintext connection to a secure TLS-encrypted channel.

Developed in the late 90s, STARTTLS worked by checking if a connection could be set up via TLS and then negotiating the TLS connection with all involved parties before sending the email data.

Although the entire STARTTLS negotiation process was fragile and prone to errors, STARTTLS came at a time when there was no broad support for encrypted connections in email clients and email servers. Lacking better alternatives at the time, most users and servers admins chose to enable STARTTLS as a temporary solution until TLS support got broader adoption across the internet.

Today, things have changed. Almost all major email clients and email servers support a pure TLS-only mode where all old protocols like POP3, IMAP, and SMTP are funneled by default via an encrypted channel that safeguards email communications from tampering or wiretapping, with email clients refusing to send emails if a secure TLS connection can't be established.

However, there are still millions of email clients and hundreds of thousands of email servers where STARTTLS is supported and still enabled.

Users advised to move from STARTTLS to TLS-only modes

In a research project presented at the USENIX 2021 security conference last week, academics said they found more than 40 vulnerabilities in STARTTLS client and server implementations that could be abused to downgrade STARTTLS connections to plaintext forms, intercept email communications, steal passwords, or tamper with email inboxes.

While these attacks required a MitM (Man/Meddler-in-the-Middle) position in order to interact with the STARTTLS initial negotiation process, the research team said that "these vulnerabilities are so common that we recommend to avoid using STARTTLS when possible" and that users and administrators should move to update their clients and servers to using TLS-only connections as soon as possible.

Thunderbird client connection security settings

The good news is that the researchers have spent the past few months working with email client and server vendors to patch the 40+ vulnerabilities they discovered.

While users have the option to apply these patches and continue using STARTTLS to be safe from attacks, researchers advise that users update their client and server settings and set TLS-only as the default email communication security setting by default, something that other security experts have also been recommending since 2014 already.

Below is a summary of the issues discovered by the research team and the affected email clients and email servers.

Summary of STARTTLS client vulnerabilities

Response Injection (Buffering)
ProductProtocolStatusLinks
Apple Mail (macOS)SMTP/POP3/IMAPFixed in macOS High Sierra 10.13.6/Big Sur 11.4CVE-2020-9941, CVE-2021-30696
Apple Mail (iOS/iPadOS)SMTP/POP3/IMAPFixed in iOS/iPadOS 14.0CVE-2020-9941
Mozilla ThunderbirdIMAPFixed in 78.7.0CVE-2020-15685, Vendor advisory, Bug report (restricted)
Claws MailSMTP/POP3/IMAPFixed in 3.17.6 for SMTP/POP3, See libEtPan for IMAPCVE-2020-15917
MuttIMAP/SMTP/POP3Fixed in 1.14.4CVE-2020-14954
NeoMuttIMAP/SMPT/POP3Fixed in 2020-06-19Commit/Patch, see also CVE-2020-14954
EvolutionSMTP/POP3Fixed in 3.36.4 (evolution-data-server)CVE-2020-14928
LibEtPan (Mail Framework for C Language)IMAP/SMTP/POP3Fixed in repository, unreleasedCVE-2020-15953
Exim (MTA sending)SMTPUnfixed (reported privately)-
Gmail (iOS/iPadOS)SMTP/IMAPUnfixed (reported privately)-
Mail.ru, MyMailSMTPUnfixed (reported privately, report closed as not applicable)-
YandexSMTP/IMAPUnfixed (reported privately)-
PHP (stream_socket_enable_crypto)SMTP/POP3/IMAPUnfixedBug report (private)
Negotiation and Tampering bugs
ProductDescriptionProtocolStatusLinks
Gmail (Android)Leak of emailsIMAPFixed (retested in 2021.07.11.387440246)-
Gmail (Go)Leak of emailsIMAPFixed (retested in 2020.10.15.341102866)-
Samsung EmailLeak of emailsIMAPFixed (untested)-
AlpineUntagged responses accepted before STARTTLSIMAPUnknown (reported via email)-
TrojitáUntagged responses accepted before STARTTLSIMAPUnknownBug report
Mozilla ThunderbirdServer responses prior to STARTTLS processedIMAPFixed in 78.12CVE-2021-29969, Vendor advisory
KMailSTARTTLS ignored when "Server requires authentication" not checkedSMTPUnknownBug report
SylpheedSTARTTLS strippingIMAPUnknownBug report
OfflineIMAPSTARTTLS strippingIMAPUnknownBug report
GMX / Web.de Mail CollectorSTARTTLS strippingPOP3/IMAPFixed-
Mail.ru, MyMail, Email app for GmailSTARTTLS StrippingSMTPUnfixed (report closed as not applicable)-
Avoiding Encryption via IMAP PREAUTH
ProductStatusLinks
Apple Mail (iOS/iPadOS)Reported February 2020, Re-reported August 2021, Unfixed-
Mozilla ThunderbirdFixed in 68.9.0CVE-2020-12398
AlpineFixed in 2.23CVE-2020-14929, Commit
MuttFixed in 1.14.3CVE-2020-14093
NeoMuttFixed in Release 2020-06-19Commit/Patch, see also CVE-2020-14093
GMX / Web.de Mail CollectorFixed-
Certificate Validation
ProductProtocolDescriptionStatusLinks
OfflineIMAPIMAPAccepts untrusted certificatesUnknownBug report
GMX / Web.de Mail CollectorPOP3/IMAPAccepts untrusted certificatesStill allows self-signed-
YandexSMTP/IMAPAccepts untrusted certificatesUnknown (report closed as not eligible)-
Mail.ru, MyMailSMTPAccepts untrusted certificates (SMTP, IMAP)Unknown (report closed as duplicate)-
Outlook (Android & iOS)SMTP/IMAPCertificate hostname not checked (SMTP, IMAP)Unknown (report closed as low/medium severity)-
GearySMTP/IMAPAccepting an untrusted certificate creates a permanent trust exception for all certificatesFixed in 3.36.3CVE-2020-24661
TrojitáSMTPAccepts untrusted certificatesFixed in repository (77ddd5d4) (no official releases)CVE-2020-15047
Ruby Net::SMTPSMTPOnly checks hostname, ignores certificate signatureFixed in 2.7.2Bug report
Crashes
ProductProtocolDescriptionStatusLinks
AlpineIMAPCrash when LIST or LSUB send before STARTTLSUnknown (reported via email)-
BalsaIMAPNullptr dereference when TLS required and PREAUTH sendFixed in 2.5.10CVE-2020-16118
BalsaIMAPStack overflow due to repeated BAD answer to CAPABILITY commandFixed in 2.6.2 (no release yet)Bug Report
BalsaIMAPCrash on untagged EXPUNGE responseFixed in commit 26e554ac (no release yet)Bug Report
EvolutionIMAPInvalid free when no auth mechanisms in greetingFixed in >3.35.91CVE-2020-16117
Miscellaneous
ProductProtocolDescriptionStatusLinks
KMailPOP3Setup wizard in POP3 defaults to unencrypted connectionsFixed in 20.08Bug Report
KMailPOP3Config shows "encrypted", but it isn'tFixedCVE-2020-15954
KMailSMTP/IMAPDialog loop "forces" the user to accept invalid certificatesUnknownBug Report
Mozilla ThunderbirdPOP3Infinite loop when POP3 server replies with -ERR to STLS commandUnknownBug Report
TrojitáSMTP/IMAPHard to choose implicit TLS due to typo (German)FixedBug Report
TrojitáSMTPSMTP defaults to plaintext on port 587UnknownBug Report

Summary of STARTTLS server vulnerabilities

Command Injection (Buffering)
ProductProtocolStatusLinks
Nemesis (used by GMX / Web.de, provider)POP3/IMAPFixed (reported privately)-
Interia.pl (provider)SMTP/POP3/IMAPFixed (reported privately)-
Yahoo (only MTA-to-MTA, provider)SMTPUnfixed (reported privately)-
Yandex (provider)SMTP/POP3/IMAPUnfixed (reported privately)-
s/qmailSMTPFixed in 4.0.09CVE-2020-15955
CoremailSMTP/POP3/IMAPUnfixed (reported via CERT)-
CitadelSMTP/POP3/IMAPUnfixedCVE-2020-29547, Bug report
Gordano GMSPOP3/IMAPUnfixedCVE-2021-37844
recvmailSMTPFixed in 3.1.2 (reported privately)-
SmarterMailPOP3Fixed in Build 7537CVE-2020-29548
Burp CollaboratorSMTPFixed in 2020.9.2Bug report, Vendor release notes
DovecotSMTPFixed in 2.3.14.1 and 2.3.15CVE-2021-33515
Mercury/32SMTP/POP3/IMAPFixed in 4.90CVE-2021-33487
QMail Toaster (1.4.1)SMTPProject discontinued-
CourierPOP3Fixed in 1.1.5 (reported privately), known since 2013Discussion from 2013, CVE-2021-38084, Fix
PHP (stream_socket_enable_crypto)SMTP/POP3/IMAPUnfixedBug report (private)
Session Fixation
ProductProtocolStatusLinks
CitadelPOP3/IMAPReported via forum, unfixedForum with report, CVE-2021-37845
IPswitch IMailPOP3/IMAPReported via Mail, unfixedCVE-2021-37846
Miscellaneous Issues
ProductProtocolDescriptionStatusLinks
Nemesis (used by GMX / Web.de, provider)SMTPAdvertises authentication before STARTTLS even though it is disabledFixed (reported via Bugbounty)-

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/starttls-implementations-in-email-clients-servers-plagued-by-40-vulnerabilities