Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: offlineimap

Found 2 matching suggestions

View:
Compact
Detailed
created 1 month ago
offlineimap before 6.3.2 does not check for SSL server certificate …

offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks.

References

Affected products

offlineimap
  • ==before 6.3.2

Matching in nixpkgs

pkgs.offlineimap

Synchronize emails between two repositories, so that you can read the same mailbox from multiple computers

created 1 month ago
offlineimap before 6.3.4 added support for SSL server certificate validation …

offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.

References

Affected products

offlineimap
  • ==before 6.3.4

Matching in nixpkgs

pkgs.offlineimap

Synchronize emails between two repositories, so that you can read the same mailbox from multiple computers