LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.6-1ubuntu0.1", "binary_name": "libetpan-dbg" }, { "binary_version": "1.6-1ubuntu0.1", "binary_name": "libetpan-dev" }, { "binary_version": "1.6-1ubuntu0.1", "binary_name": "libetpan-dev-dbgsym" }, { "binary_version": "1.6-1ubuntu0.1", "binary_name": "libetpan-doc" }, { "binary_version": "1.6-1ubuntu0.1", "binary_name": "libetpan17" }, { "binary_version": "1.6-1ubuntu0.1", "binary_name": "libetpan17-dbgsym" } ] }