Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.
CVSS Details
- CVSS 3.0 Base Score: 7.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade claws-mail | Sep 20, 2017 | Apr 11, 2016 |
| Debian | — | Upgrade macopixUpgrade claws-mail | Feb 2, 2016 | Jan 23, 2016 |
| Freebsd | — | Upgrade claws-mail | Dec 10, 2025 | Jan 19, 2016 |
| Gentoo Linux | — | Upgrade mail-client/claws-mail. | Oct 30, 2017 | Apr 11, 2016 |
| Suse | — | Upgrade claws-mailUpgrade claws-mail-langUpgrade claws-mail-develUpgrade claws-mail-debuginfoUpgrade claws-mail-debugsource | Jan 23, 2016 | Jan 2, 2016 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Apr 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub