
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-16094 affects Claws Mail through version 3.17.6. The vulnerability exists in the imap_scan_tree_recursive function, where a malicious IMAP server can trigger stack consumption due to unlimited recursion into subdirectories during a folder tree rebuild operation (NVD, Claws Bug).
The vulnerability stems from the imap_scan_tree_recursive() function which calls itself recursively without any depth limit, eventually leading to stack overflow. The issue has a CVSS v3.1 Base Score of 7.5 (High) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The vulnerability is classified as CWE-674 (Uncontrolled Recursion) (NVD).
When exploited, this vulnerability can cause the application to crash due to stack consumption. The impact is primarily on availability, with no direct effect on confidentiality or integrity. The vulnerability can be triggered during the 'Rebuild folder tree' operation when connected to a malicious IMAP server (Claws Bug).
The vulnerability can be exploited by a malicious IMAP server that presents a deeply nested directory structure. A proof of concept exists demonstrating two variants of the attack: one involving indefinite subdirectory traversal, and another involving connection termination after multiple iterations (Claws Bug).
The vulnerability was fixed in Claws Mail version 3.17.7 by implementing a recursion depth limit. The fix includes a hidden preference setting with a default depth limit of 64 levels (Claws Bug, Fedora Update).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."