Bugzilla – Bug 1174457
VUL-1: CVE-2020-15917: claws-mail: protocol violation because suffix data after STARTTLS is mishandled
Last modified: 2021-08-09 11:13:48 UTC
CVE-2020-15917 common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-15917 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15917 https://git.claws-mail.org/?p=claws.git;a=blob;f=RELEASE_NOTES https://git.claws-mail.org/?p=claws.git;a=commit;h=fcc25329049b6f9bd8d890f1197ed61eb12e14d5
This is an autogenerated message for OBS integration: This bug (1174457) was mentioned in https://build.opensuse.org/request/show/822613 15.1 / claws-mail https://build.opensuse.org/request/show/822621 15.2 / claws-mail
openSUSE-SU-2020:1116-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1174457 CVE References: CVE-2020-15917 JIRA References: Sources used: openSUSE Leap 15.1 (src): claws-mail-3.17.3-lp151.2.3.1
openSUSE-SU-2020:1139-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1174457 CVE References: CVE-2020-15917 JIRA References: Sources used: openSUSE Leap 15.2 (src): claws-mail-3.17.6-lp152.3.3.1
openSUSE-SU-2020:1269-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1174457 CVE References: CVE-2020-15917 JIRA References: Sources used: openSUSE Backports SLE-15-SP1 (src): claws-mail-3.17.3-bp151.3.3.1
openSUSE-SU-2020:1192-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1174457 CVE References: CVE-2020-15917 JIRA References: Sources used: openSUSE Backports SLE-15-SP2 (src): claws-mail-3.17.6-bp152.3.3.1
Done
openSUSE-SU-2021:1045-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1174457 CVE References: CVE-2020-15917 JIRA References: Sources used: openSUSE Leap 15.2 (src): claws-mail-3.18.0-lp152.3.9.1 openSUSE Backports SLE-15-SP3 (src): claws-mail-3.18.0-bp153.2.3.1 openSUSE Backports SLE-15-SP2 (src): claws-mail-3.18.0-bp152.3.9.1