Vulnerability record · CVE-2016-10727 · published 20 July 2018
CVE-2016-10727: Canonical ubuntu linux information exposure vulnerability
Canonical · Ubuntu Linux
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.
Description
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1334842 | ExploitIssue TrackingPatchThird Party Advisory |
| https://github.com/GNOME/evolution-data-server/releases/tag/EVOLUTION_DATA_SERVER_3_21_2 | Third Party Advisory |
| https://gitlab.gnome.org/GNOME/evolution-data-server/blob/master/NEWS#L1022 | Vendor Advisory |
| https://gitlab.gnome.org/GNOME/evolution-data-server/commit/f26a6f67 | PatchVendor Advisory |
| https://usn.ubuntu.com/3724-1/ | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1334842 | ExploitIssue TrackingPatchThird Party Advisory |
| https://github.com/GNOME/evolution-data-server/releases/tag/EVOLUTION_DATA_SERVER_3_21_2 | Third Party Advisory |
| https://gitlab.gnome.org/GNOME/evolution-data-server/blob/master/NEWS#L1022 | Vendor Advisory |
| https://gitlab.gnome.org/GNOME/evolution-data-server/commit/f26a6f67 | PatchVendor Advisory |
| https://usn.ubuntu.com/3724-1/ | Third Party Advisory |
Track CVE-2016-10727 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-10727), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.