[Bug 1174630] VUL-1: CVE-2020-16094: claws-mail: a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree
https://bugzilla.suse.com/show_bug.cgi?id=1174630 https://bugzilla.suse.com/show_bug.cgi?id=1174630#c11 Wolfgang Frisch <wolfgang.frisch@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Resolution|--- |FIXED Status|NEW |RESOLVED --- Comment #11 from Wolfgang Frisch <wolfgang.frisch@suse.com> --- (In reply to Jean Delvare from comment #10)
Upstream bugzilla was updated meanwhile. This bug is fixed in version 3.17.7, by this commit:
https://git.claws-mail.org/?p=claws.git;a=commit; h=3acca60b6efd93f23607754305a9810b56b44efd
Supported distributions are using more recent versions (3.18.0 in SLED 15 SP3 and Leap 15.3, 4.0.0 [which also includes the fix] in SLES 15 SP4 and Leap 15.4, 4.1.1 in Tumbleweed).
So I think we can close this bug. Reassigning to security team.
Thank you for checking! -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com