curl/tests/data/test985
Patrick Monnerat 364f174724
ftp,imap,pop3: do not ignore --ssl-reqd
In imap and pop3, check if TLS is required even when capabilities
request has failed.

In ftp, ignore preauthentication (230 status of server greeting) if TLS
is required.

Bug: https://curl.se/docs/CVE-2021-22946.html

CVE-2021-22946
2021-09-13 16:51:31 +02:00

55 lines
650 B
Plaintext

<testcase>
<info>
<keywords>
POP3
STARTTLS
</keywords>
</info>
#
# Server-side
<reply>
<servercmd>
REPLY CAPA -ERR Not implemented
</servercmd>
<data nocheck="yes">
From: me@somewhere
To: fake@nowhere
body
--
yours sincerely
</data>
</reply>
#
# Client-side
<client>
<features>
SSL
</features>
<server>
pop3
</server>
<name>
POP3 require STARTTLS with failing capabilities
</name>
<command>
pop3://%HOSTIP:%POP3PORT/%TESTNUMBER -u user:secret --ssl-reqd
</command>
</client>
#
# Verify data after the test has been "shot"
<verify>
# 64 is CURLE_USE_SSL_FAILED
<errorcode>
64
</errorcode>
<protocol>
CAPA
</protocol>
</verify>
</testcase>