Mail Client Vulnerability in GNOME Evolution-Data-Server
CVE-2020-16117
5.9MEDIUM
Summary
A vulnerability in GNOME's evolution-data-server affects versions prior to 3.35.91, allowing a malicious server to crash the mail client. This can occur through sending an invalid CAPABILITY line during connection attempts, which results in a NULL pointer dereference related to the imapx_free_capability and imapx_connect_to_server functions.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved