
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-16117 affects GNOME evolution-data-server before version 3.35.91. The vulnerability was discovered in July 2020 and involves a NULL pointer dereference vulnerability that can be triggered by a malicious server (NVD, CVE).
The vulnerability occurs when processing invalid CAPABILITY lines during connection attempts to a mail server. Specifically, the issue relates to the handling of minimal or invalid CAPABILITY lines in the imapx_free_capability and imapx_connect_to_server functions (CVE).
When exploited, this vulnerability allows a malicious server to cause a denial of service by crashing the mail client through a NULL pointer dereference (NVD).
The vulnerability requires interaction with a malicious server and has been rated with a CVSS score of 5.3, indicating moderate severity. The attack vector is network-based, with high attack complexity and requires user interaction (Oracle).
The vulnerability has been fixed in evolution-data-server version 3.35.91 and later. Users are advised to upgrade to the patched version. For specific distributions, security updates have been released - for example, Red Hat has addressed this in RHSA-2021:1752 (Red Hat), and Debian has fixed it in version 3.22.7-1+deb9u2 (Debian).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."