DEBIAN-CVE-2020-15954

Source
https://security-tracker.debian.org/tracker/CVE-2020-15954
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2020-15954.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2020-15954
Upstream
Downstream
Published
2020-07-27T07:15:11Z
Modified
2026-09-11T11:01:39Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.

References

Affected packages

Debian:12
kdepim-runtime

Package

Name
kdepim-runtime
Purl
pkg:deb/debian/kdepim-runtime?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4:20.04.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2020-15954.json"
kmail-account-wizard

Package

Name
kmail-account-wizard
Purl
pkg:deb/debian/kmail-account-wizard?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4:20.04.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2020-15954.json"
ksmtp

Package

Name
ksmtp
Purl
pkg:deb/debian/ksmtp?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
21.12.3-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2020-15954.json"
Debian:13
kdepim-runtime

Package

Name
kdepim-runtime
Purl
pkg:deb/debian/kdepim-runtime?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4:20.04.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2020-15954.json"
kmail-account-wizard

Package

Name
kmail-account-wizard
Purl
pkg:deb/debian/kmail-account-wizard?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4:20.04.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2020-15954.json"
ksmtp

Package

Name
ksmtp
Purl
pkg:deb/debian/ksmtp?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
21.12.3-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2020-15954.json"
Debian:14
kdepim-runtime

Package

Name
kdepim-runtime
Purl
pkg:deb/debian/kdepim-runtime?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4:20.04.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2020-15954.json"
kmail-account-wizard

Package

Name
kmail-account-wizard
Purl
pkg:deb/debian/kmail-account-wizard?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4:20.04.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2020-15954.json"
ksmtp

Package

Name
ksmtp
Purl
pkg:deb/debian/ksmtp?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
21.12.3-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2020-15954.json"