Bugzilla – Bug 959993
VUL-0: CVE-2015-8614: claws-mail: no bounds check could lead to stack overflow
Last modified: 2016-02-17 00:11:54 UTC
CVE-2015-8614 So in codeconv.c there is a function for japanese character set conversion called conv_jistoeuc(). There is no bounds checking on the output buffer, which is created on the stack with alloca(). References: http://www.thewildbeast.co.uk/claws-mail/bugzilla/show_bug.cgi?id=3557 http://seclists.org/oss-sec/2015/q4/557 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8614
bugbot adjusting priority
I am working on this, in case anyone hasn't already applied for the job ;)
https://build.opensuse.org/request/show/350619
(In reply to Atri Bhattacharya from comment #3) > https://build.opensuse.org/request/show/350619 If 13.1 and 13.2 are affected, can you please submit for these as well?
This is an autogenerated message for OBS integration: This bug (959993) was mentioned in https://build.opensuse.org/request/show/350674 42.1+13.1+13.2 / claws-mail
Thanks for pointing out, Andreas. Since upstream only committed it to the master branch I thought the bug only affected the latest version, but indeed 13.2 and 13.1 are affected too. Please see https://build.opensuse.org/request/show/350674 for the multi-target fix.
update is running
Releasing
openSUSE-SU-2016:0002-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 959993 CVE References: CVE-2015-8614 Sources used: openSUSE Leap 42.1 (src): claws-mail-3.12.0-4.1 openSUSE 13.2 (src): claws-mail-3.11.0-2.7.1 openSUSE 13.1 (src): claws-mail-3.10.1-3.8.1
openSUSE-SU-2016:0479-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 959993 CVE References: CVE-2015-8614 Sources used: openSUSE Leap 42.1 (src): claws-mail-3.12.0-7.1 openSUSE 13.2 (src): claws-mail-3.11.0-2.10.1
openSUSE-SU-2016:0485-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 959993 CVE References: CVE-2015-8614 Sources used: openSUSE 13.1 (src): claws-mail-3.11.0-3.11.1