Описание
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
A NULL pointer dereference flaw was found in the GNOME evolution-data-server when a mail client parses invalid messages from a malicious server. This flaw allows an attacker who controls a mail server the ability to crash the mail clients. The highest threat from this vulnerability is to system availability.
Отчет
The flaw requires a malicious server and it can at most make the client application crash, without additional damage to the client's data or system.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | evolution-data-server | Out of support scope | ||
| Red Hat Enterprise Linux 6 | evolution-data-server | Out of support scope | ||
| Red Hat Enterprise Linux 7 | evolution-data-server | Fix deferred | ||
| Red Hat Enterprise Linux 8 | evolution | Fixed | RHSA-2021:1752 | 18.05.2021 |
| Red Hat Enterprise Linux 8 | evolution-data-server | Fixed | RHSA-2021:1752 | 18.05.2021 |
| Red Hat Enterprise Linux 8 | evolution-ews | Fixed | RHSA-2021:1752 | 18.05.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
In GNOME evolution-data-server before 3.35.91, a malicious server can ...
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
EPSS
5.9 Medium
CVSS3