claws-mail: malicious IMAP server can trigger stack consumption (CVE-2020-16094)
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.
References:
- https://www.thewildbeast.co.uk/claws-mail/bugzilla/show_bug.cgi?id=4313
- https://security-tracker.debian.org/tracker/CVE-2020-16094
Affected branches:
-
master (50a68db6) -
3.12-stable
Edited by Leo