ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-known/autoconfig for retrieving the configuration. This is related to kmail-account-wizard.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "accountwizard", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "akonadiconsole", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "akregator", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "blogilo", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "kaddressbook", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "kalarm", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "kdepim", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "kdepim-themeeditors", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "kleopatra", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "kmail", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "knotes", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "konsolekalendar", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "kontact", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "korganizer", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "ktnef", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5calendarsupport5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5composereditorng5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5eventviews5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5followupreminder5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5gravatar5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5incidenceeditorsng5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5kdepimdbusinterfaces5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5kdgantt2-5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5kmanagesieve5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5ksieve5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5ksieveui5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5libkdepim5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5libkleo5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5mailcommon5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5mailimporter5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5messagecomposer5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5messagecore5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5messagelist5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5messageviewer5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5noteshared5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5pimcommon5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5sendlater5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "libkf5templateparser5", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" }, { "binary_name": "storageservicemanager", "binary_version": "4:15.12.3-0ubuntu1.1+esm1" } ] }