ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-known/autoconfig for retrieving the configuration. This is related to kmail-account-wizard.
{
"binaries": [
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "accountwizard"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "akonadiconsole"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "akregator"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "blogilo"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "kaddressbook"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "kalarm"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "kdepim"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "kdepim-themeeditors"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "kleopatra"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "kmail"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "knotes"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "konsolekalendar"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "kontact"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "korganizer"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "ktnef"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5calendarsupport5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5composereditorng5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5eventviews5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5followupreminder5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5gravatar5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5incidenceeditorsng5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5kdepimdbusinterfaces5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5kdgantt2-5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5kmanagesieve5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5ksieve5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5ksieveui5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5libkdepim5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5libkleo5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5mailcommon5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5mailimporter5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5messagecomposer5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5messagecore5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5messagelist5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5messageviewer5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5noteshared5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5pimcommon5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5sendlater5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "libkf5templateparser5"
},
{
"binary_version": "4:15.12.3-0ubuntu1.1+esm1",
"binary_name": "storageservicemanager"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}