Bug 1174457 - (CVE-2020-15917) VUL-1: CVE-2020-15917: claws-mail: protocol violation because suffix data after STARTTLS is mishandled
(CVE-2020-15917)
VUL-1: CVE-2020-15917: claws-mail: protocol violation because suffix data af...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P4 - Low : Normal (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/264168/
:
Depends on:
Blocks: NOSTARTTLS
  Show dependency treegraph
 
Reported: 2020-07-24 06:10 UTC by Alexandros Toptsoglou
Modified: 2021-08-09 11:13 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2020-07-24 06:10:47 UTC
CVE-2020-15917

common/session.c in Claws Mail before 3.17.6 has a protocol violation because
suffix data after STARTTLS is mishandled.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-15917
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15917
https://git.claws-mail.org/?p=claws.git;a=blob;f=RELEASE_NOTES
https://git.claws-mail.org/?p=claws.git;a=commit;h=fcc25329049b6f9bd8d890f1197ed61eb12e14d5
Comment 1 OBSbugzilla Bot 2020-07-24 12:00:07 UTC
This is an autogenerated message for OBS integration:
This bug (1174457) was mentioned in
https://build.opensuse.org/request/show/822613 15.1 / claws-mail
https://build.opensuse.org/request/show/822621 15.2 / claws-mail
Comment 2 Swamp Workflow Management 2020-07-31 19:12:36 UTC
openSUSE-SU-2020:1116-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1174457
CVE References: CVE-2020-15917
JIRA References: 
Sources used:
openSUSE Leap 15.1 (src):    claws-mail-3.17.3-lp151.2.3.1
Comment 3 Swamp Workflow Management 2020-08-03 16:14:22 UTC
openSUSE-SU-2020:1139-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1174457
CVE References: CVE-2020-15917
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    claws-mail-3.17.6-lp152.3.3.1
Comment 4 Swamp Workflow Management 2020-08-27 10:16:11 UTC
openSUSE-SU-2020:1269-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1174457
CVE References: CVE-2020-15917
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP1 (src):    claws-mail-3.17.3-bp151.3.3.1
Comment 5 Swamp Workflow Management 2020-09-18 16:43:08 UTC
openSUSE-SU-2020:1192-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1174457
CVE References: CVE-2020-15917
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP2 (src):    claws-mail-3.17.6-bp152.3.3.1
Comment 6 Alexandros Toptsoglou 2020-10-27 16:22:31 UTC
Done
Comment 7 Swamp Workflow Management 2021-07-16 01:18:12 UTC
openSUSE-SU-2021:1045-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1174457
CVE References: CVE-2020-15917
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    claws-mail-3.18.0-lp152.3.9.1
openSUSE Backports SLE-15-SP3 (src):    claws-mail-3.18.0-bp153.2.3.1
openSUSE Backports SLE-15-SP2 (src):    claws-mail-3.18.0-bp152.3.9.1