CVE-2020-16117
Summary
| CVE | CVE-2020-16117 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-29 18:15:00 UTC |
| Updated | 2020-08-11 17:29:00 UTC |
| Description | In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Crash on malformed server response with minimal capabilities (#189) · Issues · GNOME / evolution-data-server · GitLab |
MISC |
gitlab.gnome.org |
Exploit, Vendor Advisory |
| [SECURITY] [DLA 2309-1] evolution-data-server security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| I#189 - Crash on malformed server response with minimal capabilities (2cc39592) · Commits · GNOME / evolution-data-server · GitLab |
MISC |
gitlab.gnome.org |
Patch, Vendor Advisory |
| NEWS update for 3.35.91 (627c3cdb) · Commits · GNOME / evolution-data-server · GitLab |
MISC |
gitlab.gnome.org |
Release Notes, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159211 Oracle Enterprise Linux Security Update for evolution (ELSA-2021-1752)
- 174823 SUSE Enterprise Linux Security update for evolution-data-server (SUSE-SU-2021:0891-1)
- 239310 Red Hat Update for evolution (RHSA-2021:1752)
- 296071 Oracle Solaris 11.4 Support Repository Update (SRU) 27.82.1 Missing (CPUOCT2020)
- 377392 Alibaba Cloud Linux Security Update for evolution (ALINUX3-SA-2022:0095)
- 750291 OpenSUSE Security Update for evolution-data-server (openSUSE-SU-2021:0482-1)
- 940156 AlmaLinux Security Update for evolution (ALSA-2021:1752)
- 960846 Rocky Linux Security Update for evolution (RLSA-2021:1752)