aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--NEWS1
1 files changed, 1 insertions, 0 deletions
diff --git a/NEWS b/NEWS
index 46f0c550..1d7c8ca7 100644
--- a/NEWS
+++ b/NEWS
@@ -48,6 +48,7 @@ fetchmail 6.3.8 (not yet released):
* Make the APOP challenge parser more distrustful and have it reject challenges
that do not conform to RFC-822 msg-id format, in the hope to make mounting
man-in-the-middle attacks (MITM) against APOP a bit more difficult.
+ (CVE-2007-1558)
APOP is claimed insecure by Gaƫtan Leurent for MITM scenarios for typical
setups: based on MD5 collisions, it is purportedly possible to recover the