Vulnerability Details CVE-2019-8337
In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.8%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2019-8337
-
cpe:2.3:a:marlam:mpop:1.4.2
-
cpe:2.3:a:marlam:msmtp:1.8.2