CVE-2014-2576: Claws-Mail

Medium severity, CVSS 6.8. EPSS: 2% chance of exploitation in the next 30 days.

plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

Affected products

  • Claws-Mail Claws-Mail: up to and including 3.9.3
  • Opensuse Opensuse: version 12.3 only; version 13.1 only

Published 2014-10-15. Last modified 2026-06-17.