First published: Tue Jul 28 2020(Updated: )
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Claws-Mail | <=3.17.6 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16094 has been classified with a high severity rating due to the potential for denial of service through stack consumption.
To mitigate CVE-2020-16094, update Claws Mail to version 3.17.7 or later, which addresses the vulnerability.
CVE-2020-16094 affects Claws Mail versions up to and including 3.17.6.
CVE-2020-16094 affects Claws Mail on various Linux distributions, including Fedora 31, 32, and 33.
CVE-2020-16094 is caused by unchecked recursion into subdirectories during the rebuilding of the folder tree in Claws Mail.