Related Vulnerabilities: CVE-2021-37746  

textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.

Severity Medium

Remote Yes

Type Insufficient validation

Description

textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.

AVG-2244 sylpheed 3.7.0-4 Medium Vulnerable

AVG-2243 claws-mail 3.17.8-2 3.18.0-1 Medium Fixed

https://git.claws-mail.org/?p=claws.git;a=commitdiff;h=ac286a71ed78429e16c612161251b9ea90ccd431