{"id":"UBUNTU-CVE-2021-38373","details":"In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless \"Server requires authentication\" is checked.","modified":"2026-04-22T12:59:45.395996Z","published":"2021-08-10T15:15:00Z","upstream":["CVE-2021-38373"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-38373"},{"type":"REPORT","url":"https://bugs.kde.org/show_bug.cgi?id=423423"},{"type":"REPORT","url":"https://nostarttls.secvuln.info"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-38373"},{"type":"REPORT","url":"https://kde.org/info/security/advisory-20211118-1.txt"}],"affected":[{"package":{"name":"kmailtransport","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/kmailtransport@17.12.3-0ubuntu4?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["17.04.3-0ubuntu1","17.08.3-0ubuntu2","17.08.3-0ubuntu3","17.12.2-0ubuntu1","17.12.3-0ubuntu3","17.12.3-0ubuntu4"],"ecosystem_specific":{"binaries":[{"binary_name":"kde-config-mailtransport","binary_version":"17.12.3-0ubuntu4"},{"binary_name":"kmailtransport-akonadi","binary_version":"17.12.3-0ubuntu4"},{"binary_version":"17.12.3-0ubuntu4","binary_name":"libkf5mailtransport-data"},{"binary_name":"libkf5mailtransport5abi2","binary_version":"17.12.3-0ubuntu4"},{"binary_name":"libkf5mailtransportakonadi5","binary_version":"17.12.3-0ubuntu4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-38373.json"}},{"package":{"name":"ksmtp","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/ksmtp@17.12.2-0ubuntu1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["17.12.2-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"libkpimsmtp5","binary_version":"17.12.2-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-38373.json"}},{"package":{"name":"kmailtransport","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/kmailtransport@19.12.3-0ubuntu1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["19.04.3-0ubuntu1","19.04.3-0ubuntu2","19.12.3-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"19.12.3-0ubuntu1","binary_name":"kde-config-mailtransport"},{"binary_name":"kmailtransport-akonadi","binary_version":"19.12.3-0ubuntu1"},{"binary_version":"19.12.3-0ubuntu1","binary_name":"libkf5mailtransport-data"},{"binary_name":"libkf5mailtransport5abi2","binary_version":"19.12.3-0ubuntu1"},{"binary_name":"libkf5mailtransportakonadi5","binary_version":"19.12.3-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-38373.json"}},{"package":{"name":"ksmtp","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/ksmtp@19.12.3-0ubuntu2?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["19.04.3-0ubuntu1","19.04.3-0ubuntu2","19.12.3-0ubuntu1","19.12.3-0ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"libkpimsmtp5abi1","binary_version":"19.12.3-0ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-38373.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}