Mail Notification 4.0, when WITH_SSL is set to 0 at compile time, uses unencrypted connections for accounts configured with SSL/TLS, which allows remote attackers to obtain sensitive information by sniffing the network.Referenceshttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=428157http://secunia.com/advisories/25600http://osvdb.org/37205https://exchange.xforce.ibmcloud.com/vulnerabilities/34814https://savannah.nongnu.org/bugs/index.php?20131