5
CVSSv2

CVE-2020-16094

Published: 28/07/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In imap_scan_tree_recursive in Claws Mail up to and including 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

claws-mail claws-mail

fedoraproject fedora 31

fedoraproject fedora 32

fedoraproject fedora 33

Vendor Advisories

Debian Bug report logs - #966630 claws-mail: CVE-2020-16094 Package: src:claws-mail; Maintainer for src:claws-mail is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 31 Jul 2020 18:51:01 UTC Severity: important Tags: security, upstream Found in version claws-mail/3 ...