First published: Fri Jul 30 2021(Updated: )
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Claws-Mail | <3.18.0 | |
Sylpheed | <=3.7.0 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37746 is classified as a medium severity vulnerability due to insufficient link checks in Claws Mail and Sylpheed.
To fix CVE-2021-37746, update Claws Mail to version 3.18.0 or later, or Sylpheed to version 3.7.1 or later.
CVE-2021-37746 affects Claws Mail versions before 3.18.0 and Sylpheed versions up to 3.7.0.
The risks of CVE-2021-37746 include the execution of malicious links without proper security checks, potentially leading to phishing or malware exposure.
Yes, a patch for CVE-2021-37746 is included in the updates for Claws Mail version 3.18.0 and Sylpheed version 3.7.1.