CVE-2016-10727

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-10727
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10727.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-10727
Related
Published
2018-07-20T04:29:00Z
Modified
2025-01-08T10:00:58.486963Z
Downstream
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.

References

Affected packages

Debian:11 / evolution-data-server

Package

Name
evolution-data-server
Purl
pkg:deb/debian/evolution-data-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.22.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / evolution-data-server

Package

Name
evolution-data-server
Purl
pkg:deb/debian/evolution-data-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.22.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / evolution-data-server

Package

Name
evolution-data-server
Purl
pkg:deb/debian/evolution-data-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.22.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/gnome/evolution

Affected ranges

Type
GIT
Repo
https://github.com/gnome/evolution
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/gnome/evolution-data-server
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://gitlab.gnome.org/GNOME/evolution-data-server
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

Other

BEFORE_NEW_UI_MERGE
DB_4_1_25_NC
DROOLING_MACAQUE
ECALCOMP_ABI_ANCHOR
EDS_MODULES_BASE
EVOLUION_1_5_4
EVOLUTION_0_0
EVOLUTION_0_1
EVOLUTION_0_12
EVOLUTION_0_13
EVOLUTION_0_14
EVOLUTION_0_15
EVOLUTION_0_16
EVOLUTION_0_16_100
EVOLUTION_0_2
EVOLUTION_0_3
EVOLUTION_0_5
EVOLUTION_0_6
EVOLUTION_0_8
EVOLUTION_0_99_0
EVOLUTION_0_99_2
EVOLUTION_1_0_7
EVOLUTION_1_0_8
EVOLUTION_1_1_1
EVOLUTION_1_1_90
EVOLUTION_1_2_0
EVOLUTION_1_2_3
EVOLUTION_1_3_1
EVOLUTION_1_3_2
EVOLUTION_1_3_3
EVOLUTION_1_3_91
EVOLUTION_1_3_92
EVOLUTION_1_4_0
EVOLUTION_1_4_1
EVOLUTION_1_4_2
EVOLUTION_1_4_3
EVOLUTION_1_4_4
EVOLUTION_1_5
EVOLUTION_1_5_1
EVOLUTION_1_5_2
EVOLUTION_1_5_3
EVOLUTION_1_5_5
EVOLUTION_1_5_6
EVOLUTION_1_5_6_1
EVOLUTION_1_5_8
EVOLUTION_1_5_90
EVOLUTION_1_5_91
EVOLUTION_1_5_92
EVOLUTION_1_5_92_1
EVOLUTION_1_5_92_2
EVOLUTION_1_5_93
EVOLUTION_1_5_94
EVOLUTION_1_5_94_1
EVOLUTION_2_0_0
EVOLUTION_2_0_2
EVOLUTION_2_0_3
EVOLUTION_2_0_4
EVOLUTION_2_11_3
EVOLUTION_2_11_4
EVOLUTION_2_11_5
EVOLUTION_2_11_90
EVOLUTION_2_11_91
EVOLUTION_2_11_92
EVOLUTION_2_1_0
EVOLUTION_2_1_1
EVOLUTION_2_1_2
EVOLUTION_2_1_3
EVOLUTION_2_1_3_1
EVOLUTION_2_1_4
EVOLUTION_2_1_5
EVOLUTION_2_21_1
EVOLUTION_2_21_2
EVOLUTION_2_21_3
EVOLUTION_2_21_4
EVOLUTION_2_21_90
EVOLUTION_2_21_91
EVOLUTION_2_22_0
EVOLUTION_2_23_1
EVOLUTION_2_23_2
EVOLUTION_2_23_3
EVOLUTION_2_23_4
EVOLUTION_2_23_5
EVOLUTION_2_23_6
EVOLUTION_2_23_90
EVOLUTION_2_23_91
EVOLUTION_2_25_1
EVOLUTION_2_25_2
EVOLUTION_2_25_3
EVOLUTION_2_25_4
EVOLUTION_2_25_5
EVOLUTION_2_25_90
EVOLUTION_2_25_92
EVOLUTION_2_26_0
EVOLUTION_2_26_1
EVOLUTION_2_27_3
EVOLUTION_2_27_4
EVOLUTION_2_27_5
EVOLUTION_2_27_90
EVOLUTION_2_29_1
EVOLUTION_2_29_3
EVOLUTION_2_29_3_1
EVOLUTION_2_29_4
EVOLUTION_2_29_5
EVOLUTION_2_29_6
EVOLUTION_2_29_90
EVOLUTION_2_29_92
EVOLUTION_2_30_0
EVOLUTION_2_30_0_1
EVOLUTION_2_30_1
EVOLUTION_2_31_1
EVOLUTION_2_31_2_CORRECTED
EVOLUTION_2_31_3
EVOLUTION_2_31_3_1
EVOLUTION_2_31_4
EVOLUTION_2_31_5_CORRECTED
EVOLUTION_2_31_6
EVOLUTION_2_31_90
EVOLUTION_2_31_91
EVOLUTION_2_31_92
EVOLUTION_2_91_0
EVOLUTION_2_91_1
EVOLUTION_2_91_2
EVOLUTION_2_91_3
EVOLUTION_2_91_4
EVOLUTION_2_91_5
EVOLUTION_2_91_6
EVOLUTION_2_91_90
EVOLUTION_2_91_91
EVOLUTION_2_91_92
EVOLUTION_3_10_0
EVOLUTION_3_11_1
EVOLUTION_3_11_2
EVOLUTION_3_11_3
EVOLUTION_3_11_4
EVOLUTION_3_11_5
EVOLUTION_3_11_90
EVOLUTION_3_11_91
EVOLUTION_3_12_0
EVOLUTION_3_13_1
EVOLUTION_3_13_10
EVOLUTION_3_13_2
EVOLUTION_3_13_3
EVOLUTION_3_13_4
EVOLUTION_3_13_5
EVOLUTION_3_13_6
EVOLUTION_3_13_7
EVOLUTION_3_13_8
EVOLUTION_3_13_9
EVOLUTION_3_13_90
EVOLUTION_3_15_91
EVOLUTION_3_15_92
EVOLUTION_3_16_0
EVOLUTION_3_17_1
EVOLUTION_3_17_2
EVOLUTION_3_17_3
EVOLUTION_3_17_4
EVOLUTION_3_17_90
EVOLUTION_3_17_91
EVOLUTION_3_17_92
EVOLUTION_3_18_0
EVOLUTION_3_19_1
EVOLUTION_3_19_2
EVOLUTION_3_19_3
EVOLUTION_3_19_4
EVOLUTION_3_19_90
EVOLUTION_3_19_91
EVOLUTION_3_19_92
EVOLUTION_3_1_1
EVOLUTION_3_1_3
EVOLUTION_3_1_4
EVOLUTION_3_1_5
EVOLUTION_3_1_90_FIXED
EVOLUTION_3_1_91
EVOLUTION_3_1_92
EVOLUTION_3_20_0
EVOLUTION_3_21_1
EVOLUTION_3_2_0
EVOLUTION_3_3_2
EVOLUTION_3_3_3
EVOLUTION_3_3_4
EVOLUTION_3_3_5
EVOLUTION_3_3_90
EVOLUTION_3_3_91
EVOLUTION_3_3_92
EVOLUTION_3_4_0
EVOLUTION_3_5_1
EVOLUTION_3_5_3
EVOLUTION_3_5_4
EVOLUTION_3_5_5
EVOLUTION_3_5_90
EVOLUTION_3_5_91
EVOLUTION_3_5_92
EVOLUTION_3_7_1
EVOLUTION_3_7_2_FIXED
EVOLUTION_3_7_3
EVOLUTION_3_7_4_FIXED
EVOLUTION_3_7_90
EVOLUTION_3_7_91
EVOLUTION_3_7_92
EVOLUTION_3_9_2
EVOLUTION_3_9_3
EVOLUTION_3_9_4
EVOLUTION_3_9_5
EVOLUTION_3_9_90
EVOLUTION_3_9_91
EVOLUTION_3_9_92
EVOLUTION_DATA_SERVER_0_0_2
EVOLUTION_DATA_SERVER_0_0_3
EVOLUTION_DATA_SERVER_0_0_4
EVOLUTION_DATA_SERVER_0_0_5
EVOLUTION_DATA_SERVER_0_0_6
EVOLUTION_DATA_SERVER_0_0_7
EVOLUTION_DATA_SERVER_0_0_90
EVOLUTION_DATA_SERVER_0_0_91
EVOLUTION_DATA_SERVER_0_0_93
EVOLUTION_DATA_SERVER_0_0_96
EVOLUTION_DATA_SERVER_0_0_97
EVOLUTION_DATA_SERVER_0_0_98
EVOLUTION_DATA_SERVER_0_0_99
EVOLUTION_DATA_SERVER_1_11_3
EVOLUTION_DATA_SERVER_1_11_4
EVOLUTION_DATA_SERVER_1_11_5
EVOLUTION_DATA_SERVER_1_11_90
EVOLUTION_DATA_SERVER_1_11_91
EVOLUTION_DATA_SERVER_1_11_92
EVOLUTION_DATA_SERVER_1_1_0
EVOLUTION_DATA_SERVER_1_1_1
EVOLUTION_DATA_SERVER_1_1_2
EVOLUTION_DATA_SERVER_1_1_3
EVOLUTION_DATA_SERVER_1_1_4
EVOLUTION_DATA_SERVER_1_1_5
EVOLUTION_DATA_SERVER_1_1_6
EVOLUTION_DATA_SERVER_1_3_1
EVOLUTION_DATA_SERVER_1_3_2
EVOLUTION_DATA_SERVER_1_3_3
EVOLUTION_DATA_SERVER_1_3_3_1
EVOLUTION_DATA_SERVER_1_3_4
EVOLUTION_DATA_SERVER_1_3_5
EVOLUTION_DATA_SERVER_1_3_6
EVOLUTION_DATA_SERVER_1_3_6_1
EVOLUTION_DATA_SERVER_1_3_7
EVOLUTION_DATA_SERVER_1_3_8
EVOLUTION_DATA_SERVER_1_5_1
EVOLUTION_DATA_SERVER_1_5_3
EVOLUTION_DATA_SERVER_1_5_4
EVOLUTION_DATA_SERVER_1_5_5
EVOLUTION_DATA_SERVER_1_5_91
EVOLUTION_DATA_SERVER_1_5_92
EVOLUTION_DATA_SERVER_1_5_9_0
EVOLUTION_DATA_SERVER_1_7_1
EVOLUTION_DATA_SERVER_1_7_2
EVOLUTION_DATA_SERVER_1_7_3
EVOLUTION_DATA_SERVER_1_7_4
EVOLUTION_DATA_SERVER_1_7_90
EVOLUTION_DATA_SERVER_1_7_90_1
EVOLUTION_DATA_SERVER_1_7_91
EVOLUTION_DATA_SERVER_1_7_92
EVOLUTION_DATA_SERVER_1_8_0
EVOLUTION_DATA_SERVER_1_8_1
EVOLUTION_DATA_SERVER_1_9_1
EVOLUTION_DATA_SERVER_1_9_3
EVOLUTION_DATA_SERVER_2_21_1
EVOLUTION_DATA_SERVER_2_21_2
EVOLUTION_DATA_SERVER_2_21_3
EVOLUTION_DATA_SERVER_2_21_4
EVOLUTION_DATA_SERVER_2_21_5
EVOLUTION_DATA_SERVER_2_21_90
EVOLUTION_DATA_SERVER_2_21_91
EVOLUTION_DATA_SERVER_2_22_0
EVOLUTION_DATA_SERVER_2_23_1
EVOLUTION_DATA_SERVER_2_23_2
EVOLUTION_DATA_SERVER_2_23_3
EVOLUTION_DATA_SERVER_2_23_4
EVOLUTION_DATA_SERVER_2_23_5
EVOLUTION_DATA_SERVER_2_23_6
EVOLUTION_DATA_SERVER_2_23_90
EVOLUTION_DATA_SERVER_2_23_91
EVOLUTION_DATA_SERVER_2_25_1
EVOLUTION_DATA_SERVER_2_25_2
EVOLUTION_DATA_SERVER_2_25_3
EVOLUTION_DATA_SERVER_2_25_4
EVOLUTION_DATA_SERVER_2_25_5
EVOLUTION_DATA_SERVER_2_25_90
EVOLUTION_DATA_SERVER_2_25_92
EVOLUTION_DATA_SERVER_2_26_0
EVOLUTION_DATA_SERVER_2_27_2
EVOLUTION_DATA_SERVER_2_27_3
EVOLUTION_DATA_SERVER_2_27_4
EVOLUTION_DATA_SERVER_2_27_5
EVOLUTION_DATA_SERVER_2_27_90
EVOLUTION_DATA_SERVER_2_29_1
EVOLUTION_DATA_SERVER_2_29_2
EVOLUTION_DATA_SERVER_2_29_3
EVOLUTION_DATA_SERVER_2_29_4
EVOLUTION_DATA_SERVER_2_29_5
EVOLUTION_DATA_SERVER_2_29_6
EVOLUTION_DATA_SERVER_2_29_90
EVOLUTION_DATA_SERVER_2_29_91
EVOLUTION_DATA_SERVER_2_29_92
EVOLUTION_DATA_SERVER_2_31_1
EVOLUTION_DATA_SERVER_2_31_2
EVOLUTION_DATA_SERVER_2_31_3
EVOLUTION_DATA_SERVER_2_31_3_1
EVOLUTION_DATA_SERVER_2_31_4
EVOLUTION_DATA_SERVER_2_31_5
EVOLUTION_DATA_SERVER_2_31_6
EVOLUTION_DATA_SERVER_2_31_90
EVOLUTION_DATA_SERVER_2_31_91
EVOLUTION_DATA_SERVER_2_31_92
EVOLUTION_DATA_SERVER_2_91_0
EVOLUTION_DATA_SERVER_2_91_1
EVOLUTION_DATA_SERVER_2_91_2
EVOLUTION_DATA_SERVER_2_91_3
EVOLUTION_DATA_SERVER_2_91_4
EVOLUTION_DATA_SERVER_2_91_5
EVOLUTION_DATA_SERVER_2_91_6
EVOLUTION_DATA_SERVER_2_91_90
EVOLUTION_DATA_SERVER_2_91_91
EVOLUTION_DATA_SERVER_2_91_92
EVOLUTION_DATA_SERVER_3_10_0
EVOLUTION_DATA_SERVER_3_11_1
EVOLUTION_DATA_SERVER_3_11_2
EVOLUTION_DATA_SERVER_3_11_3
EVOLUTION_DATA_SERVER_3_11_4
EVOLUTION_DATA_SERVER_3_11_5
EVOLUTION_DATA_SERVER_3_11_90
EVOLUTION_DATA_SERVER_3_11_91
EVOLUTION_DATA_SERVER_3_11_92
EVOLUTION_DATA_SERVER_3_12_0
EVOLUTION_DATA_SERVER_3_13_1
EVOLUTION_DATA_SERVER_3_13_10
EVOLUTION_DATA_SERVER_3_13_2
EVOLUTION_DATA_SERVER_3_13_3
EVOLUTION_DATA_SERVER_3_13_4
EVOLUTION_DATA_SERVER_3_13_5
EVOLUTION_DATA_SERVER_3_13_6
EVOLUTION_DATA_SERVER_3_13_7
EVOLUTION_DATA_SERVER_3_13_8
EVOLUTION_DATA_SERVER_3_13_9
EVOLUTION_DATA_SERVER_3_13_90
EVOLUTION_DATA_SERVER_3_15_91
EVOLUTION_DATA_SERVER_3_15_92
EVOLUTION_DATA_SERVER_3_16_0
EVOLUTION_DATA_SERVER_3_17_1
EVOLUTION_DATA_SERVER_3_17_2
EVOLUTION_DATA_SERVER_3_17_3
EVOLUTION_DATA_SERVER_3_17_4
EVOLUTION_DATA_SERVER_3_17_90
EVOLUTION_DATA_SERVER_3_17_91
EVOLUTION_DATA_SERVER_3_17_92
EVOLUTION_DATA_SERVER_3_18_0
EVOLUTION_DATA_SERVER_3_19_1
EVOLUTION_DATA_SERVER_3_19_2
EVOLUTION_DATA_SERVER_3_19_3
EVOLUTION_DATA_SERVER_3_19_4
EVOLUTION_DATA_SERVER_3_19_90
EVOLUTION_DATA_SERVER_3_19_91
EVOLUTION_DATA_SERVER_3_19_92
EVOLUTION_DATA_SERVER_3_1_2
EVOLUTION_DATA_SERVER_3_1_3
EVOLUTION_DATA_SERVER_3_1_3_1
EVOLUTION_DATA_SERVER_3_1_4
EVOLUTION_DATA_SERVER_3_1_5
EVOLUTION_DATA_SERVER_3_1_90
EVOLUTION_DATA_SERVER_3_1_91
EVOLUTION_DATA_SERVER_3_1_92
EVOLUTION_DATA_SERVER_3_20_0
EVOLUTION_DATA_SERVER_3_21_1
EVOLUTION_DATA_SERVER_3_2_0
EVOLUTION_DATA_SERVER_3_3_1
EVOLUTION_DATA_SERVER_3_3_2
EVOLUTION_DATA_SERVER_3_3_3
EVOLUTION_DATA_SERVER_3_3_4
EVOLUTION_DATA_SERVER_3_3_5
EVOLUTION_DATA_SERVER_3_3_90
EVOLUTION_DATA_SERVER_3_3_91
EVOLUTION_DATA_SERVER_3_3_92
EVOLUTION_DATA_SERVER_3_4_0
EVOLUTION_DATA_SERVER_3_5_1
EVOLUTION_DATA_SERVER_3_5_3
EVOLUTION_DATA_SERVER_3_5_4
EVOLUTION_DATA_SERVER_3_5_5_FIXED
EVOLUTION_DATA_SERVER_3_5_90
EVOLUTION_DATA_SERVER_3_5_91
EVOLUTION_DATA_SERVER_3_5_92
EVOLUTION_DATA_SERVER_3_7_1
EVOLUTION_DATA_SERVER_3_7_2
EVOLUTION_DATA_SERVER_3_7_3
EVOLUTION_DATA_SERVER_3_7_4
EVOLUTION_DATA_SERVER_3_7_5
EVOLUTION_DATA_SERVER_3_7_90
EVOLUTION_DATA_SERVER_3_7_92
EVOLUTION_DATA_SERVER_3_9_1
EVOLUTION_DATA_SERVER_3_9_2
EVOLUTION_DATA_SERVER_3_9_3
EVOLUTION_DATA_SERVER_3_9_4
EVOLUTION_DATA_SERVER_3_9_5
EVOLUTION_DATA_SERVER_3_9_90
EVOLUTION_DATA_SERVER_3_9_91
EVOLUTION_DATA_SERVER_3_9_92
E_TREE_REWORK_BASE
GNOME_0_12
GNOME_0_20
GNOME_0_20a
GNOME_0_25
GNOME_0_27
GNOME_2_16_BRANCHPOINT
GNOME_MEDIA_1_2_2
GNOME_PRINT_0_24
INITIAL
LWE_2001_01
MEEGO_1_0
ROSALIA_BEFORE_COMMITTING_DL_AND_GNOME_HELLO
V0_0_1
backend-split-branch-merge-start
before-camel-mt
before-eds-merge
caldav-branchpoint
eds-1-0-1-merge-start
eds-1-2-1-merge-start
evolution-2-0-1-merge
evolution-2-0-1-merge-start
gnome-2-10-base
gnome-2-8-base
mmapped-camel-summary-branchpoint
new-calendar-branch-before-create-modify
new-calendar-branch-merge-end
new-calendar-branch-start
new-parser-anchor
new-ui-branch-merge-end
new-ui-branch-merge-start
notzed-disksummary-branchpoint
notzed-eplugin-2-merge
notzed-messageinfo-branchpoint
spam-filtering-start
toshok-libmimedir-base