CVE-2020-15917: Critical severity mambo cms vulnerability
Published Jul 23, 2020
·Updated
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
Affected Software
7 affected components
claws-mail claws-mail<3.17.6
Fedoraproject Fedora=31
Fedoraproject Fedora=32
openSUSE Backports SLE=15.0-sp1
openSUSE Backports SLE=15.0-sp2
openSUSE Leap=15.1
openSUSE Leap=15.2
Remediation
Event History
Jul 23, 2020
CVE Published
via MITRE·06:06 PM
Data Sourced
via MITRE·06:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-15917?
CVE-2020-15917 has a moderate severity rating due to the protocol violation issues.
2
How do I fix CVE-2020-15917?
To fix CVE-2020-15917, upgrade Claws Mail to version 3.17.6 or later.
3
What versions of Claws Mail are affected by CVE-2020-15917?
CVE-2020-15917 affects all versions of Claws Mail prior to 3.17.6.
4
What is the nature of the vulnerability in CVE-2020-15917?
The vulnerability in CVE-2020-15917 is a protocol violation caused by mishandling suffix data after the STARTTLS command.
5
Which operating systems are impacted by CVE-2020-15917?
CVE-2020-15917 impacts Fedora versions 31 and 32, and specific versions of openSUSE.