Bug 1174711 - (CVE-2020-16118) VUL-1: CVE-2020-16118: balsa: a malicious server or MITM can trigger a NULL pointer dereference
(CVE-2020-16118)
VUL-1: CVE-2020-16118: balsa: a malicious server or MITM can trigger a NULL p...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P4 - Low : Normal (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/264508/
:
Depends on:
Blocks: NOSTARTTLS
  Show dependency treegraph
 
Reported: 2020-07-30 07:55 UTC by Wolfgang Frisch
Modified: 2021-08-09 11:42 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Frisch 2020-07-30 07:55:24 UTC
CVE-2020-16118

In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle
can trigger a NULL pointer dereference and client crash by sending a PREAUTH
response to imap_mbox_connect in libbalsa/imap/imap-handle.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-16118
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16118
https://gitlab.gnome.org/GNOME/balsa/-/commit/4e245d758e1c826a01080d40c22ca8706f0339e5
https://gitlab.gnome.org/GNOME/balsa/-/issues/23
Comment 1 Wolfgang Frisch 2020-07-30 07:56:09 UTC
Affects openSUSE:Leap:15.1 only.
Comment 2 OBSbugzilla Bot 2020-08-10 12:20:06 UTC
This is an autogenerated message for OBS integration:
This bug (1174711) was mentioned in
https://build.opensuse.org/request/show/825371 15.1 / balsa
Comment 3 Swamp Workflow Management 2020-08-14 19:23:02 UTC
openSUSE-SU-2020:1207-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1174711
CVE References: CVE-2020-16118
JIRA References: 
Sources used:
openSUSE Leap 15.1 (src):    balsa-2.5.5-lp151.3.3.1
Comment 4 Swamp Workflow Management 2020-08-18 10:15:24 UTC
openSUSE-SU-2020:1230-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1174711
CVE References: CVE-2020-16118
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP1 (src):    balsa-2.5.5-bp151.4.3.1
Comment 5 Bjørn Lie 2020-08-25 19:35:31 UTC
Updates released, closing as resolved fixed.