CVE-2007-1137
 
Severity Score
5.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain sensitive information.
putmail.py en Putmail anterior a 1.4 no detecta cuando un usuario intenta utilizar TLS con un servidor que no lo soporta, lo cual provoca que putmail.py envíe el nombre de usuario y contraseña en texto plano mientras que el usuario cree que se está usando cifrado, y permite a atacantes remotos obtener información sensible.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-02-27 CVE Reserved
- 2007-02-27 CVE Published
- 2024-04-24 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://osvdb.org/33764 | Vdb Entry | |
http://putmail.sourceforge.net/home.html | X_refsource_confirm | |
http://www.securityfocus.com/bid/22718 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/0753 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/32689 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/24266 | 2017-07-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sourceforge Search vendor "Sourceforge" | Putmail Search vendor "Sourceforge" for product "Putmail" | .8 Search vendor "Sourceforge" for product "Putmail" and version ".8" | - |
Affected
| ||||||
Sourceforge Search vendor "Sourceforge" | Putmail Search vendor "Sourceforge" for product "Putmail" | .9 Search vendor "Sourceforge" for product "Putmail" and version ".9" | - |
Affected
| ||||||
Sourceforge Search vendor "Sourceforge" | Putmail Search vendor "Sourceforge" for product "Putmail" | .10 Search vendor "Sourceforge" for product "Putmail" and version ".10" | - |
Affected
| ||||||
Sourceforge Search vendor "Sourceforge" | Putmail Search vendor "Sourceforge" for product "Putmail" | .11 Search vendor "Sourceforge" for product "Putmail" and version ".11" | - |
Affected
| ||||||
Sourceforge Search vendor "Sourceforge" | Putmail Search vendor "Sourceforge" for product "Putmail" | .12 Search vendor "Sourceforge" for product "Putmail" and version ".12" | - |
Affected
| ||||||
Sourceforge Search vendor "Sourceforge" | Putmail Search vendor "Sourceforge" for product "Putmail" | 1.0 Search vendor "Sourceforge" for product "Putmail" and version "1.0" | - |
Affected
| ||||||
Sourceforge Search vendor "Sourceforge" | Putmail Search vendor "Sourceforge" for product "Putmail" | 1.1 Search vendor "Sourceforge" for product "Putmail" and version "1.1" | - |
Affected
| ||||||
Sourceforge Search vendor "Sourceforge" | Putmail Search vendor "Sourceforge" for product "Putmail" | 1.2 Search vendor "Sourceforge" for product "Putmail" and version "1.2" | - |
Affected
| ||||||
Sourceforge Search vendor "Sourceforge" | Putmail Search vendor "Sourceforge" for product "Putmail" | 1.3 Search vendor "Sourceforge" for product "Putmail" and version "1.3" | - |
Affected
|