{"id":"CVE-2020-24661","details":"GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the middle to present a different invalid certificate to intercept incoming and outgoing mail.","modified":"2026-05-28T04:05:33.717110011Z","published":"2020-08-26T16:15:12.760Z","related":["openSUSE-SU-2024:10781-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*"],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora","extracted_events":[{"last_affected":"31"},{"last_affected":"32"}]}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G7OTYTGND6EFOKNQJWCHKKXKSN7SM73Y/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS6CSTOBVO5HSAR3X5CT6DS6QDHXDB26/"},{"type":"WEB","url":"https://tools.cisco.com/security/center/content/CiscoSeg/message/NS6CSTOBVO5HSAR3X5CT6DS6QDHXDB26/"},{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/geary/-/issues/866"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/geary","events":[{"introduced":"0"},{"fixed":"17f2129fe9cf96cbb00b4c38b5174e9bbd30f118"}],"database_specific":{"cpe":"cpe:2.3:a:gnome:geary:*:*:*:*:*:*:*:*","source":"CPE_RANGE","extracted_events":[{"introduced":"0"},{"fixed":"3.36.3"}]}}],"versions":["3.36.2","3.36.1","3.36.0","3.35.90","3.35.2","3.35.1","geary-3.33.91","geary-3.33.90","geary-3.33.1","geary-0.12.0","geary-0.11.0","0.11.0","geary-0.10.0","geary-0.9.1","geary-0.9.0","geary-0.8.0","geary-0.7.2","geary-0.7.1","geary-0.7.0","geary-0.6.0","geary-0.5.3","geary-0.5.2","geary-0.5.1","geary-0.5.0","geary-0.4.0","geary-0.4.0pr2","geary-0.4.0pr1","geary-0.2.0","geary-0.1.90","geary-0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-24661.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}