PT-2020-14746 · Claws Mail Team+1 · Claws Mail+1

Hanno Boeck

·

Published

2020-07-28

·

Updated

2022-01-04

·

CVE-2020-16094

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Claws Mail versions prior to 3.17.7
Description A malicious IMAP server can cause stack consumption in Claws Mail due to unlimited recursion into subdirectories during a rebuild of the folder tree. This occurs in the imap scan tree recursive function.
Recommendations For Claws Mail versions prior to 3.17.7, update to version 3.17.7 or later to resolve the issue.

Exploit

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2897
ALT-PU-2020-2978
ALT-PU-2021-3520
CVE-2020-16094
MGASA-2020-0391

Affected Products

Alt Linux
Claws Mail