In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server. Upstream patch: https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/2cc39592b532cf0dc994fd3694b8e6bf924c9ab5 https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/627c3cdbfd077e59aa288c85ff8272950577f1d7 Upstream issue: https://gitlab.gnome.org/GNOME/evolution-data-server/-/issues/189
Created evolution-data-server tracking bugs for this issue: Affects: fedora-all [bug 1862127]
(In reply to Pedro Sampaio from comment #1) > Affects: fedora-all [bug 1862127] This is not accurate, the Fedora 32 contains evolution-data-server 3.36.4, which does contain the fix (as it's after 3.35.91 and from the same base branch). Similarly for Fedora 33 (rawhide) with 3.37.3 at the moment. The only affected is Fedora 31, with evolution-data-server 3.34.4.
Statement: The flaw requires a malicious server and it can at most make the client application crash, without additional damage to the client's data or system.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-16117
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:1752 https://access.redhat.com/errata/RHSA-2021:1752