evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
"extracted_events": [
{
"last_affected": "16.04"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"extracted_events": [
{
"last_affected": "18.04"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*",
"extracted_events": [
{
"last_affected": "20.04"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "10.0"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "9.0"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "31"
}
]
}
]
}{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:gnome:evolution-data-server:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "3.36.3"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-14928.json"
[
{
"id": "CVE-2020-14928-00cf56ed",
"target": {
"file": "src/camel/providers/smtp/camel-smtp-transport.c"
},
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"88811326310142647714676084967060802531",
"233058444095276551268480870019437245082",
"87833723440427189052487113379568843383",
"239470605046030276584359078389400509066"
]
},
"source": "https://gitlab.gnome.org/gnome/evolution-data-server@ba82be72cfd427b5d72ff21f929b3a6d8529c4df",
"signature_version": "v1"
},
{
"id": "CVE-2020-14928-379bdecb",
"target": {
"file": "src/camel/providers/pop3/camel-pop3-store.c"
},
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"88811326310142647714676084967060802531",
"233058444095276551268480870019437245082",
"87833723440427189052487113379568843383",
"239470605046030276584359078389400509066"
]
},
"source": "https://gitlab.gnome.org/gnome/evolution-data-server@f404f33fb01b23903c2bbb16791c7907e457fbac",
"signature_version": "v1"
},
{
"id": "CVE-2020-14928-417b8fd5",
"target": {
"file": "src/camel/providers/pop3/camel-pop3-stream.h"
},
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"199493910500933765285989127410700280543",
"304399716984885611769796334484523229609",
"204210384105609217637402259819136612502"
]
},
"source": "https://gitlab.gnome.org/gnome/evolution-data-server@ba82be72cfd427b5d72ff21f929b3a6d8529c4df",
"signature_version": "v1"
},
{
"id": "CVE-2020-14928-441b3cfd",
"target": {
"file": "src/camel/camel-stream-buffer.h"
},
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"89053395832605180317808392096232514143",
"315417799224738764391106050296556767095",
"126232431020561451696029856354429749299"
]
},
"source": "https://gitlab.gnome.org/gnome/evolution-data-server@f404f33fb01b23903c2bbb16791c7907e457fbac",
"signature_version": "v1"
},
{
"id": "CVE-2020-14928-4b45f823",
"target": {
"function": "connect_to_server",
"file": "src/camel/providers/smtp/camel-smtp-transport.c"
},
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "272762691641719020593453431005942035644",
"length": 3722.0
},
"source": "https://gitlab.gnome.org/gnome/evolution-data-server@ba82be72cfd427b5d72ff21f929b3a6d8529c4df",
"signature_version": "v1"
},
{
"id": "CVE-2020-14928-89932039",
"target": {
"file": "src/camel/providers/pop3/camel-pop3-store.c"
},
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"88811326310142647714676084967060802531",
"233058444095276551268480870019437245082",
"87833723440427189052487113379568843383",
"239470605046030276584359078389400509066"
]
},
"source": "https://gitlab.gnome.org/gnome/evolution-data-server@ba82be72cfd427b5d72ff21f929b3a6d8529c4df",
"signature_version": "v1"
},
{
"id": "CVE-2020-14928-99267e32",
"target": {
"function": "connect_to_server",
"file": "src/camel/providers/pop3/camel-pop3-store.c"
},
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "191466675488590993705201311477623422795",
"length": 2674.0
},
"source": "https://gitlab.gnome.org/gnome/evolution-data-server@ba82be72cfd427b5d72ff21f929b3a6d8529c4df",
"signature_version": "v1"
},
{
"id": "CVE-2020-14928-a6b298eb",
"target": {
"file": "src/camel/providers/pop3/camel-pop3-stream.h"
},
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"199493910500933765285989127410700280543",
"304399716984885611769796334484523229609",
"204210384105609217637402259819136612502"
]
},
"source": "https://gitlab.gnome.org/gnome/evolution-data-server@f404f33fb01b23903c2bbb16791c7907e457fbac",
"signature_version": "v1"
},
{
"id": "CVE-2020-14928-bf170218",
"target": {
"function": "connect_to_server",
"file": "src/camel/providers/pop3/camel-pop3-store.c"
},
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "191466675488590993705201311477623422795",
"length": 2674.0
},
"source": "https://gitlab.gnome.org/gnome/evolution-data-server@f404f33fb01b23903c2bbb16791c7907e457fbac",
"signature_version": "v1"
},
{
"id": "CVE-2020-14928-dda5c845",
"target": {
"file": "src/camel/camel-stream-buffer.h"
},
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"89053395832605180317808392096232514143",
"315417799224738764391106050296556767095",
"126232431020561451696029856354429749299"
]
},
"source": "https://gitlab.gnome.org/gnome/evolution-data-server@ba82be72cfd427b5d72ff21f929b3a6d8529c4df",
"signature_version": "v1"
},
{
"id": "CVE-2020-14928-e442f18b",
"target": {
"function": "connect_to_server",
"file": "src/camel/providers/smtp/camel-smtp-transport.c"
},
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "272762691641719020593453431005942035644",
"length": 3722.0
},
"source": "https://gitlab.gnome.org/gnome/evolution-data-server@f404f33fb01b23903c2bbb16791c7907e457fbac",
"signature_version": "v1"
},
{
"id": "CVE-2020-14928-e7605d48",
"target": {
"file": "src/camel/providers/smtp/camel-smtp-transport.c"
},
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"88811326310142647714676084967060802531",
"233058444095276551268480870019437245082",
"87833723440427189052487113379568843383",
"239470605046030276584359078389400509066"
]
},
"source": "https://gitlab.gnome.org/gnome/evolution-data-server@f404f33fb01b23903c2bbb16791c7907e457fbac",
"signature_version": "v1"
}
]
"2026-05-13T11:14:04Z"