Updated claw-mail packages fix a security vulnerability
Publication date: 21 Oct 2020Type: security
Affected Mageia releases : 7
CVE: CVE-2020-16094
Description
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree (CVE-2020-16094).
References
SRPMS
7/core
- claws-mail-3.17.7-1.mga7