CVE-2020-16117
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-16117 affects GNOME evolution-data-server before version 3.35.91. The vulnerability was discovered in July 2020 and involves a NULL pointer dereference vulnerability that can be triggered by a malicious server (NVD, CVE).

Technical details

The vulnerability occurs when processing invalid CAPABILITY lines during connection attempts to a mail server. Specifically, the issue relates to the handling of minimal or invalid CAPABILITY lines in the imapx_free_capability and imapx_connect_to_server functions (CVE).

Impact

When exploited, this vulnerability allows a malicious server to cause a denial of service by crashing the mail client through a NULL pointer dereference (NVD).

Exploitability

The vulnerability requires interaction with a malicious server and has been rated with a CVSS score of 5.3, indicating moderate severity. The attack vector is network-based, with high attack complexity and requires user interaction (Oracle).

Mitigation and workarounds

The vulnerability has been fixed in evolution-data-server version 3.35.91 and later. Users are advised to upgrade to the patched version. For specific distributions, security updates have been released - for example, Red Hat has addressed this in RHSA-2021:1752 (Red Hat), and Debian has fixed it in version 3.22.7-1+deb9u2 (Debian).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-72898CRITICAL10
  • NixOS logoNixOS
  • metabase
YesYesAug 10, 2026
CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util-sqlite-debuginfo
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util-odbc
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util-mysql
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management