FreeBSD : kdelibs4 -- KMail/KIO POP3 SSL Man-in-the-middle Flaw (4a114331-0d24-11e4-8dd2-5453ed2e2b49)

Medium Nessus Plugin ID 76543


The remote FreeBSD host is missing a security-related update.


Richard J. Moore reports :

The POP3 kioslave used by KMail will accept invalid certificates without presenting a dialog to the user due a bug that leads to an inability to display the dialog combined with an error in the way the result is checked.

This flaw allows an active attacker to perform MITM attacks against the ioslave which could result in the leakage of sensitive data such as the authentication details and the contents of emails.


Update the affected package.

See Also

Plugin Details

Severity: Medium

ID: 76543

File Name: freebsd_pkg_4a1143310d2411e48dd25453ed2e2b49.nasl

Version: $Revision: 1.1 $

Type: local

Published: 2014/07/17

Modified: 2014/07/17

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:kdelibs, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/07/16

Vulnerability Publication Date: 2014/06/17

Reference Information

CVE: CVE-2014-3494

BID: 68113