CVE-2020-16117

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
29/07/2020
Last modified:
11/08/2020

Description

In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnome:evolution-data-server:*:*:*:*:*:*:*:* 3.35.91 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*