Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Untriaged
created 1 month ago
offlineimap before 6.3.2 does not check for SSL server certificate …

offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks.

References

Affected products

offlineimap
  • ==before 6.3.2

Matching in nixpkgs

pkgs.offlineimap

Synchronize emails between two repositories, so that you can read the same mailbox from multiple computers