STARTTLS implementations in email clients & servers plagued by 40+ vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-12398 | If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted con If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2020-14093 | Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response. Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response. NVD description · AI analysis pending | 5.9 | 2% |
| — | ||
| CVE-2020-14928 | evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection." NVD description · AI analysis pending | 5.9 | 3% | PoC |
| — | |
| CVE-2020-14929 | Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behav Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2020-14954 | Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection." NVD description · AI analysis pending | 5.9 | 2% |
| — | ||
| CVE-2020-15047 | MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers. MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers. NVD description · AI analysis pending | 5.9 | <1% |
| — | ||
| CVE-2020-15685 | During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2020-15917 | common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled. common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2020-15953 | LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection." NVD description · AI analysis pending | 7.4 | 2% | PoC |
| — | |
| CVE-2020-15954 | KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use. KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2020-15955 | In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker. NVD description · AI analysis pending | 5.9 | <1% |
| — | ||
| CVE-2020-16117 | In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server. NVD description · AI analysis pending | 5.9 | 2% | PoC |
| — | |
| CVE-2020-16118 | In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH respo In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — | |
| CVE-2020-24661 | GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificat GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the middle to present a different invalid certificate to intercept incoming and outgoing mail. NVD description · AI analysis pending | 5.9 | <1% | PoC |
| — | |
| CVE-2020-9941 | This issue was addressed with improved checks. This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. A remote attacker may be able to unexpectedly alter application state. NVD description · AI analysis pending | 7.5 | 3% |
| — | ||
| CVE-2021-29969 | If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS han If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders that didn't exist on the IMAP server. This vulnerability affects Thunderbird < 78.12. NVD description · AI analysis pending | 5.9 | 1% |
| — | ||
| CVE-2021-30696 | An attacker in a privileged network position may be able to misrepresent application state. An attacker in a privileged network position may be able to misrepresent application state. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A logic issue was addressed with improved state management. NVD description · AI analysis pending | 5.9 | 1% |
| — |
Full article1,275 words · extracted from therecord.media · click to collapse
A group of German academics said they discovered more than 40 security flaws in the implementation of the STARTTLS feature in today's most popular email clients and email servers. Also known as Opportunistic TLS, STARTTLS refers to a set of protocol extensions used by email clients and servers to upgrade older email protocols like POP3, IMAP, and SMTP from sending data via a plaintext connection to a secure TLS-encrypted channel. Developed in the late 90s, STARTTLS worked by checking if a connection could be set up via TLS and then negotiating the TLS connection with all involved parties before sending the email data. Although the entire STARTTLS negotiation process was fragile and prone to errors, STARTTLS came at a time when there was no broad support for encrypted connections in email clients and email servers. Lacking better alternatives at the time, most users and servers admins chose to enable STARTTLS as a temporary solution until TLS support got broader adoption across the internet. Today, things have changed. Almost all major email clients and email servers support a pure TLS-only mode where all old protocols like POP3, IMAP, and SMTP are funneled by default via an encrypted channel that safeguards email communications from tampering or wiretapping, with email clients refusing to send emails if a secure TLS connection can't be established. However, there are still millions of email clients and hundreds of thousands of email servers where STARTTLS is supported and still enabled. In a research project presented at the USENIX 2021 security conference last week, academics said they found more than 40 vulnerabilities in STARTTLS client and server implementations that could be abused to downgrade STARTTLS connections to plaintext forms, intercept email communications, steal passwords, or tamper with email inboxes. While these attacks required a MitM (Man/Meddler-in-the-Middle) position in order to interact with the STARTTLS initial negotiation process, the research team said that "these vulnerabilities are so common that we recommend to avoid using STARTTLS when possible" and that users and administrators should move to update their clients and servers to using TLS-only connections as soon as possible. The good news is that the researchers have spent the past few months working with email client and server vendors to patch the 40+ vulnerabilities they discovered. While users have the option to apply these patches and continue using STARTTLS to be safe from attacks, researchers advise that users update their client and server settings and set TLS-only as the default email communication security setting by default, something that other security experts have also been recommending since 2014 already. Below is a summary of the issues discovered by the research team and the affected email clients and email servers.Users advised to move from STARTTLS to TLS-only modes
Summary of STARTTLS client vulnerabilities
Response Injection (Buffering)
Product Protocol Status Links Apple Mail (macOS) SMTP/POP3/IMAP Fixed in macOS High Sierra 10.13.6/Big Sur 11.4 CVE-2020-9941, CVE-2021-30696 Apple Mail (iOS/iPadOS) SMTP/POP3/IMAP Fixed in iOS/iPadOS 14.0 CVE-2020-9941 Mozilla Thunderbird IMAP Fixed in 78.7.0 CVE-2020-15685, Vendor advisory, Bug report (restricted) Claws Mail SMTP/POP3/IMAP Fixed in 3.17.6 for SMTP/POP3, See libEtPan for IMAP CVE-2020-15917 Mutt IMAP/SMTP/POP3 Fixed in 1.14.4 CVE-2020-14954 NeoMutt IMAP/SMPT/POP3 Fixed in 2020-06-19 Commit/Patch, see also CVE-2020-14954 Evolution SMTP/POP3 Fixed in 3.36.4 (evolution-data-server) CVE-2020-14928 LibEtPan (Mail Framework for C Language) IMAP/SMTP/POP3 Fixed in repository, unreleased CVE-2020-15953 Exim (MTA sending) SMTP Unfixed (reported privately) - Gmail (iOS/iPadOS) SMTP/IMAP Unfixed (reported privately) - Mail.ru, MyMail SMTP Unfixed (reported privately, report closed as not applicable) - Yandex SMTP/IMAP Unfixed (reported privately) - PHP (stream_socket_enable_crypto) SMTP/POP3/IMAP Unfixed Bug report (private) Negotiation and Tampering bugs
Product Description Protocol Status Links Gmail (Android) Leak of emails IMAP Fixed (retested in 2021.07.11.387440246) - Gmail (Go) Leak of emails IMAP Fixed (retested in 2020.10.15.341102866) - Samsung Email Leak of emails IMAP Fixed (untested) - Alpine Untagged responses accepted before STARTTLS IMAP Unknown (reported via email) - Trojitá Untagged responses accepted before STARTTLS IMAP Unknown Bug report Mozilla Thunderbird Server responses prior to STARTTLS processed IMAP Fixed in 78.12 CVE-2021-29969, Vendor advisory KMail STARTTLS ignored when "Server requires authentication" not checked SMTP Unknown Bug report Sylpheed STARTTLS stripping IMAP Unknown Bug report OfflineIMAP STARTTLS stripping IMAP Unknown Bug report GMX / Web.de Mail Collector STARTTLS stripping POP3/IMAP Fixed - Mail.ru, MyMail, Email app for Gmail STARTTLS Stripping SMTP Unfixed (report closed as not applicable) - Avoiding Encryption via IMAP PREAUTH
Product Status Links Apple Mail (iOS/iPadOS) Reported February 2020, Re-reported August 2021, Unfixed - Mozilla Thunderbird Fixed in 68.9.0 CVE-2020-12398 Alpine Fixed in 2.23 CVE-2020-14929, Commit Mutt Fixed in 1.14.3 CVE-2020-14093 NeoMutt Fixed in Release 2020-06-19 Commit/Patch, see also CVE-2020-14093 GMX / Web.de Mail Collector Fixed - Certificate Validation
Product Protocol Description Status Links OfflineIMAP IMAP Accepts untrusted certificates Unknown Bug report GMX / Web.de Mail Collector POP3/IMAP Accepts untrusted certificates Still allows self-signed - Yandex SMTP/IMAP Accepts untrusted certificates Unknown (report closed as not eligible) - Mail.ru, MyMail SMTP Accepts untrusted certificates (SMTP, IMAP) Unknown (report closed as duplicate) - Outlook (Android & iOS) SMTP/IMAP Certificate hostname not checked (SMTP, IMAP) Unknown (report closed as low/medium severity) - Geary SMTP/IMAP Accepting an untrusted certificate creates a permanent trust exception for all certificates Fixed in 3.36.3 CVE-2020-24661 Trojitá SMTP Accepts untrusted certificates Fixed in repository (77ddd5d4) (no official releases) CVE-2020-15047 Ruby Net::SMTP SMTP Only checks hostname, ignores certificate signature Fixed in 2.7.2 Bug report Crashes
Product Protocol Description Status Links Alpine IMAP Crash when LIST or LSUB send before STARTTLS Unknown (reported via email) - Balsa IMAP Nullptr dereference when TLS required and PREAUTH send Fixed in 2.5.10 CVE-2020-16118 Balsa IMAP Stack overflow due to repeated BAD answer to CAPABILITY command Fixed in 2.6.2 (no release yet) Bug Report Balsa IMAP Crash on untagged EXPUNGE response Fixed in commit 26e554ac (no release yet) Bug Report Evolution IMAP Invalid free when no auth mechanisms in greeting Fixed in >3.35.91 CVE-2020-16117 Miscellaneous
Product Protocol Description Status Links KMail POP3 Setup wizard in POP3 defaults to unencrypted connections Fixed in 20.08 Bug Report KMail POP3 Config shows "encrypted", but it isn't Fixed CVE-2020-15954 KMail SMTP/IMAP Dialog loop "forces" the user to accept invalid certificates Unknown Bug Report Mozilla Thunderbird POP3 Infinite loop when POP3 server replies with -ERR to STLS command Unknown Bug Report Trojitá SMTP/IMAP Hard to choose implicit TLS due to typo (German) Fixed Bug Report Trojitá SMTP SMTP defaults to plaintext on port 587 Unknown Bug Report Summary of STARTTLS server vulnerabilities
Command Injection (Buffering)
Product Protocol Status Links Nemesis (used by GMX / Web.de, provider) POP3/IMAP Fixed (reported privately) - Interia.pl (provider) SMTP/POP3/IMAP Fixed (reported privately) - Yahoo (only MTA-to-MTA, provider) SMTP Unfixed (reported privately) - Yandex (provider) SMTP/POP3/IMAP Unfixed (reported privately) - s/qmail SMTP Fixed in 4.0.09 CVE-2020-15955 Coremail SMTP/POP3/IMAP Unfixed (reported via CERT) - Citadel SMTP/POP3/IMAP Unfixed CVE-2020-29547, Bug report Gordano GMS POP3/IMAP Unfixed CVE-2021-37844 recvmail SMTP Fixed in 3.1.2 (reported privately) - SmarterMail POP3 Fixed in Build 7537 CVE-2020-29548 Burp Collaborator SMTP Fixed in 2020.9.2 Bug report, Vendor release notes Dovecot SMTP Fixed in 2.3.14.1 and 2.3.15 CVE-2021-33515 Mercury/32 SMTP/POP3/IMAP Fixed in 4.90 CVE-2021-33487 QMail Toaster (1.4.1) SMTP Project discontinued - Courier POP3 Fixed in 1.1.5 (reported privately), known since 2013 Discussion from 2013, CVE-2021-38084, Fix PHP (stream_socket_enable_crypto) SMTP/POP3/IMAP Unfixed Bug report (private) Session Fixation
Product Protocol Status Links Citadel POP3/IMAP Reported via forum, unfixed Forum with report, CVE-2021-37845 IPswitch IMail POP3/IMAP Reported via Mail, unfixed CVE-2021-37846 Miscellaneous Issues
Product Protocol Description Status Links Nemesis (used by GMX / Web.de, provider) SMTP Advertises authentication before STARTTLS even though it is disabled Fixed (reported via Bugbounty) -
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/starttls-implementations-in-email-clients-servers-plagued-by-40-vulnerabilities