PT-2020-14757 · Gnome+7 · Evolution Data Server+7

Published

2020-03-15

·

Updated

2024-06-15

·

CVE-2020-16117

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions evolution-data-server versions prior to 3.35.91
Description A malicious server can cause the mail client to crash with a NULL pointer dereference by sending an invalid CAPABILITY line on a connection attempt. This issue is related to the imapx free capability and imapx connect to server functions.
Recommendations For versions prior to 3.35.91, update to version 3.35.91 or later to resolve the issue. As a temporary workaround, consider restricting access to untrusted servers to minimize the risk of exploitation.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:1752
ALT-PU-2020-1482
CESA-2021_1752
CVE-2020-16117
DLA-2309-1
MGASA-2020-0351
OESA-2022-1628
OPENSUSE-SU-2021:0482-1
OPENSUSE-SU-2021_0482-1
OPENSUSE-SU-2024:10744-1
RHSA-2021:1752
RHSA-2021_1752
RLSA-2021:1752
SUSE-SU-2021:0885-1
SUSE-SU-2021:0891-1
SUSE-SU-2021:0949-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Red Hat
Rocky Linux
Suse
Evolution Data Server