Asymmetric denial of service In evolution-data-server
Description
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 3.36.0-1 | ||
debian 12 | 3.36.0-1 | ||
debian 14 | 3.36.0-1 | ||
debian 13 | 3.36.0-1 | ||
rpm rhel8 | 0:3.28.5-16.el8 | ||
rpm rhel5 | - | - | |
rpm rhel6 | - | - | |
rpm rhel7 | - | - | |
rpm rhel8 | 0:3.28.5-15.el8 | ||
rpm rhel8 | 0:3.28.5-10.el8 |
Aliases
1. 2. 3. 4. 5.