Vulnerabilities > CVE-2013-4584 - Improper Handling of Exceptional Conditions vulnerability in multiple products
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://access.redhat.com/security/cve/cve-2013-4584
- https://security-tracker.debian.org/tracker/CVE-2013-4584
- http://www.openwall.com/lists/oss-security/2013/11/15/6
- http://www.securityfocus.com/bid/63696
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89184
- https://github.com/horms/perdition/commit/62a0ce94aeb7dd99155882956ce9e327ab914ddf