CVE-2014-2567: Trojita Project Trojita

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

The OpenConnectionTask::handleStateHelper function in Imap/Tasks/OpenConnectionTask.cpp in Trojita before 0.4.1 allows man-in-the-middle attackers to trigger use of cleartext for saving a message into a (1) sent or (2) draft folder via a PREAUTH response that prevents later use of the STARTTLS command.

Affected products

  • Trojita Project Trojita: up to and including 0.4; version 0.1 only; version 0.2 only; version 0.2.9 only; version 0.2.9.1 only; version 0.2.9.2 only; …

Published 2014-03-21. Last modified 2026-06-17.