From 3cf7c3ef441822c889356fd1812ebf2944a59851 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Tue, 25 Aug 2020 10:45:55 +0100 Subject: gentoo resync : 25.08.2020 --- metadata/glsa/glsa-202007-56.xml | 48 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 metadata/glsa/glsa-202007-56.xml (limited to 'metadata/glsa/glsa-202007-56.xml') diff --git a/metadata/glsa/glsa-202007-56.xml b/metadata/glsa/glsa-202007-56.xml new file mode 100644 index 000000000000..f71973e186f1 --- /dev/null +++ b/metadata/glsa/glsa-202007-56.xml @@ -0,0 +1,48 @@ + + + + Claws Mail: Improper STARTTLS handling + A vulnerability was discovered in Claws Mail's STARTTLS handling, + possibly allowing an integrity/confidentiality compromise. + + claws-mail + 2020-07-28 + 2020-07-28 + 733684 + remote + + + 3.17.6 + 3.17.6 + + + +

Claws Mail is a GTK based e-mail client.

+
+ +

It was discovered that Claws Mail was not properly handling state within + the STARTTLS protocol handshake. +

+
+ +

There may be a breach of integrity or confidentiality in connections + made using Claws Mail with STARTTLS. +

+
+ +

There is no known workaround at this time.

+
+ +

All Claws Mail users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=mail-client/claws-mail-3.17.6" + +
+ + CVE-2020-15917 + + sam_c + sam_c +
-- cgit v1.2.3