Medium severity5.9NVD Advisory· Published Jul 17, 2020· Updated Jun 17, 2026
CVE-2020-14928
CVE-2020-14928
Description
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21cpe:2.3:a:gnome:evolution-data-server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gnome:evolution-data-server:*:*:*:*:*:*:*:*range: <=3.36.3
- (no CPE)range: <=3.36.3
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- evolution-data-server/evolution-data-serverdescription
- osv-coords12 versionspkg:rpm/almalinux/bogofilterpkg:rpm/almalinux/evolution-data-server-docpkg:rpm/almalinux/evolution-data-server-perlpkg:rpm/almalinux/evolution-data-server-testspkg:rpm/almalinux/evolution-develpkg:rpm/opensuse/evolution-data-server&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/evolution-data-server&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/evolution-ews&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/evolution-data-server&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/evolution-data-server&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5pkg:rpm/suse/evolution-data-server&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2pkg:rpm/suse/evolution-ews&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2
< 1.2.5-2.el8+ 11 more
- (no CPE)range: < 1.2.5-2.el8
- (no CPE)range: < 3.28.5-14.el8
- (no CPE)range: < 3.28.5-14.el8
- (no CPE)range: < 3.28.5-14.el8
- (no CPE)range: < 3.28.5-14.el8
- (no CPE)range: < 3.34.4-lp152.2.3.1
- (no CPE)range: < 3.40.4-1.4
- (no CPE)range: < 3.34.4-lp152.2.3.1
- (no CPE)range: < 3.22.7-18.7.1
- (no CPE)range: < 3.20.6-17.3.1
- (no CPE)range: < 3.34.4-3.3.1
- (no CPE)range: < 3.34.4-3.3.1
Patches
Vulnerability mechanics
References
10- bugzilla.suse.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- gitlab.gnome.org/GNOME//evolution-data-server/commit/ba82be72cfd427b5d72ff21f929b3a6d8529c4dfnvdPatchThird Party Advisory
- gitlab.gnome.org/GNOME/evolution-data-server/-/commit/f404f33fb01b23903c2bbb16791c7907e457fbacnvdPatchThird Party Advisory
- gitlab.gnome.org/GNOME/evolution-data-server/-/issues/226nvdExploitThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/07/msg00012.htmlnvdMailing ListThird Party Advisory
- security-tracker.debian.org/tracker/DLA-2281-1nvdThird Party Advisory
- security-tracker.debian.org/tracker/DSA-4725-1nvdThird Party Advisory
- usn.ubuntu.com/4429-1/nvdThird Party Advisory
- www.debian.org/security/2020/dsa-4725nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QMBEZWA22EAYAZQWUX4KPEBER726KSIG/nvd
News mentions
0No linked articles in our index yet.