Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-16118

Опубликовано: 29 июл. 2020
Источник: debian

Описание

In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
balsafixed2.6.0-1package
balsano-dsabusterpackage
balsano-dsastretchpackage

Примечания

  • https://gitlab.gnome.org/GNOME/balsa/-/commit/4e245d758e1c826a01080d40c22ca8706f0339e5

  • https://gitlab.gnome.org/GNOME/balsa/-/issues/23

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.

CVSS3: 7.5
nvd
больше 5 лет назад

In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.

suse-cvrf
больше 5 лет назад

Security update for balsa

CVSS3: 7.5
github
больше 3 лет назад

In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.