First published: Wed Jul 29 2020(Updated: )
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME evolution-data-server | <3.35.91 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16117 is a vulnerability in GNOME evolution-data-server before version 3.35.91 that allows a malicious server to crash the mail client with a NULL pointer dereference.
CVE-2020-16117 affects GNOME evolution-data-server versions before 3.35.91.
A malicious server can exploit CVE-2020-16117 by sending an invalid CAPABILITY line on a connection attempt.
CVE-2020-16117 has a severity rating of medium, with a CVSS score of 5.9.
Yes, the vulnerability has been fixed in GNOME evolution-data-server version 3.35.91.