PT-2020-14758 · Gnome+1 · Gnome Balsa+1

Published

2020-07-29

·

Updated

2023-02-03

·

CVE-2020-16118

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNOME Balsa versions prior to 2.6.0
Description A malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap mbox connect in libbalsa/imap/imap-handle.c. This issue can be exploited to cause a client crash.
Recommendations For versions prior to 2.6.0, update to version 2.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to untrusted servers to minimize the risk of exploitation.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2020-16118
OPENSUSE-SU-2020:1207-1
OPENSUSE-SU-2020:1230-1
OPENSUSE-SU-2020_1207-1

Affected Products

Gnome Balsa
Suse