Back to Database
Status published
Medium
CVE-2013-4584
Perdition before 2.2 may have weak security when handling outbound...
Vulnerability Description
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-4584
Credits & Attribution
No credits recorded in the NVD database.
References
- https://security-tracker.debian.org/tracker/CVE-2013-4584
- https://access.redhat.com/security/cve/cve-2013-4584
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89184
- http://www.openwall.com/lists/oss-security/2013/11/15/6
- http://www.securityfocus.com/bid/63696
- https://github.com/horms/perdition/commit/62a0ce94aeb7dd99155882956ce9e327ab914ddf
Affected Vendor
Perdition
View all reports →Affected Software
Perdition
Vulnerable Versions:
before 2.2
Timeline
Official Publish:
November 15th, 2019
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.