MGASA-2020-0346 - Updated kdepim-runtime and kmail-account-wizard packages fix security vulnerability Publication date: 25 Aug 2020 URL: https://advisories.mageia.org/MGASA-2020-0346.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-15954 It was discovered that there was an issue where kmail would default to using unencrypted POP3 communication despite the UI indicating that encryption was in use (CVE-2020-15954). References: - https://bugs.mageia.org/show_bug.cgi?id=27035 - https://www.debian.org/lts/security/2020/dla-2300 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15954 SRPMS: - 7/core/kmail-account-wizard-19.04.0-1.1.mga7 - 7/core/kdepim-runtime-19.04.0-1.2.mga7