CVE-2020-16117
published 2020-07-29CVE-2020-16117: In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g.…
PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
2.12%
79.9th percentile
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | evolution-data-server | < evolution-data-server 3.36.0-1 (bookworm) | evolution-data-server 3.36.0-1 (bookworm) |
| gnome | evolution-data-server | < 3.35.91 | 3.35.91 |
| gnome | evolution-data-server | >= 0 < 3.36.0-1 | 3.36.0-1 |
| gnome | evolution-data-server | >= 0 < 3.36.0-1 | 3.36.0-1 |
| gnome | evolution-data-server | >= 0 < 3.36.0-1 | 3.36.0-1 |
| gnome | evolution-data-server | >= 0 < 3.36.0-1 | 3.36.0-1 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j89v-2w65-5qmq: In GNOME evolution-data-server before 3
ghsa_unreviewed·2022-05-24
CVE-2020-16117 [MEDIUM] GHSA-j89v-2w65-5qmq: In GNOME evolution-data-server before 3
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
OSV
CVE-2020-16117: In GNOME evolution-data-server before 3
osv·2020-07-29·CVSS 5.9
CVE-2020-16117 [MEDIUM] CVE-2020-16117: In GNOME evolution-data-server before 3
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
Red Hat
evolution-data-server: NULL pointer dereference related to imapx_free_capability and imapx_connect_to_server
vendor_redhat·2020-07-30·CVSS 5.9
CVE-2020-16117 [MEDIUM] CWE-476 evolution-data-server: NULL pointer dereference related to imapx_free_capability and imapx_connect_to_server
evolution-data-server: NULL pointer dereference related to imapx_free_capability and imapx_connect_to_server
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
A NULL pointer dereference flaw was found in the GNOME evolution-data-server when a mail client parses invalid messages from a malicious server. This flaw allows an attacker who controls a mail server the ability to crash the mail clients. The highest threat from this vulnerability is to system availability.
Statement: The flaw requires a malicious server and it can at most make the client application crash, wit
Debian
CVE-2020-16117: evolution-data-server - In GNOME evolution-data-server before 3.35.91, a malicious server can crash the ...
vendor_debian·2020·CVSS 5.9
CVE-2020-16117 [MEDIUM] CVE-2020-16117: evolution-data-server - In GNOME evolution-data-server before 3.35.91, a malicious server can crash the ...
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
Scope: local
bookworm: resolved (fixed in 3.36.0-1)
bullseye: resolved (fixed in 3.36.0-1)
forky: resolved (fixed in 3.36.0-1)
sid: resolved (fixed in 3.36.0-1)
trixie: resolved (fixed in 3.36.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-16117 evolution-data-server: NULL pointer dereference related to imapx_free_capability and imapx_connect_to_server
bugzilla·2020-07-30·CVSS 5.9
CVE-2020-16117 [MEDIUM] CVE-2020-16117 evolution-data-server: NULL pointer dereference related to imapx_free_capability and imapx_connect_to_server
CVE-2020-16117 evolution-data-server: NULL pointer dereference related to imapx_free_capability and imapx_connect_to_server
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
Upstream patch:
https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/2cc39592b532cf0dc994fd3694b8e6bf924c9ab5
https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/627c3cdbfd077e59aa288c85ff8272950577f1d7
Upstream issue:
https://gitlab.gnome.org/GNOME/evolution-data-server/-/issues/189
Discussion:
Created evolution-data-server tracking bugs for this issue:
Affects: fedora-all
Bugzilla
CVE-2020-16117 evolution-data-server: NULL pointer dereference elated to imapx_free_capability and imapx_connect_to_server [fedora-all]
bugzilla·2020-07-30·CVSS 5.9
CVE-2020-16117 [MEDIUM] CVE-2020-16117 evolution-data-server: NULL pointer dereference elated to imapx_free_capability and imapx_connect_to_server [fedora-all]
CVE-2020-16117 evolution-data-server: NULL pointer dereference elated to imapx_free_capability and imapx_connect_to_server [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mess
https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/2cc39592b532cf0dc994fd3694b8e6bf924c9ab5https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/627c3cdbfd077e59aa288c85ff8272950577f1d7https://gitlab.gnome.org/GNOME/evolution-data-server/-/issues/189https://lists.debian.org/debian-lts-announce/2020/08/msg00005.htmlhttps://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/2cc39592b532cf0dc994fd3694b8e6bf924c9ab5https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/627c3cdbfd077e59aa288c85ff8272950577f1d7https://gitlab.gnome.org/GNOME/evolution-data-server/-/issues/189https://lists.debian.org/debian-lts-announce/2020/08/msg00005.html
2020-07-29
Published