diff options
-rw-r--r-- | NEWS | 1 |
1 files changed, 1 insertions, 0 deletions
@@ -48,6 +48,7 @@ fetchmail 6.3.8 (not yet released): * Make the APOP challenge parser more distrustful and have it reject challenges that do not conform to RFC-822 msg-id format, in the hope to make mounting man-in-the-middle attacks (MITM) against APOP a bit more difficult. + (CVE-2007-1558) APOP is claimed insecure by Gaƫtan Leurent for MITM scenarios for typical setups: based on MD5 collisions, it is purportedly possible to recover the |