CVE-2021-37746: Medium severity claws-mail claws-mail vulnerability
Published Jul 30, 2021
·Updated
textviewurisecuritycheck in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
Affected Software
4 affected components
claws-mail claws-mail<3.18.0
Sylpheed Project Sylpheed<=3.7.0
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Remediation
Event History
Jul 30, 2021
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-37746?
CVE-2021-37746 is classified as a medium severity vulnerability due to insufficient link checks in Claws Mail and Sylpheed.
2
How do I fix CVE-2021-37746?
To fix CVE-2021-37746, update Claws Mail to version 3.18.0 or later, or Sylpheed to version 3.7.1 or later.
3
Which software versions are affected by CVE-2021-37746?
CVE-2021-37746 affects Claws Mail versions before 3.18.0 and Sylpheed versions up to 3.7.0.
4
What are the potential risks of CVE-2021-37746?
The risks of CVE-2021-37746 include the execution of malicious links without proper security checks, potentially leading to phishing or malware exposure.
5
Is there a patch available for CVE-2021-37746?
Yes, a patch for CVE-2021-37746 is included in the updates for Claws Mail version 3.18.0 and Sylpheed version 3.7.1.