common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade claws-mail | Aug 10, 2020 | Jul 23, 2020 |
| Debian | — | Upgrade claws-mail | Jul 30, 2024 | Jul 23, 2020 |
| Gentoo Linux | — | Upgrade mail-client/claws-mail. | Jul 29, 2020 | Jul 23, 2020 |
| Suse | — | Upgrade claws-mail-develUpgrade claws-mail-langUpgrade claws-mail | Aug 1, 2020 | Jul 23, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub