Claws Mail: Improper STARTTLS handling A vulnerability was discovered in Claws Mail's STARTTLS handling, possibly allowing an integrity/confidentiality compromise. claws-mail 2020-07-28 2020-07-28 733684 remote 3.17.6 3.17.6

Claws Mail is a GTK based e-mail client.

It was discovered that Claws Mail was not properly handling state within the STARTTLS protocol handshake.

There may be a breach of integrity or confidentiality in connections made using Claws Mail with STARTTLS.

There is no known workaround at this time.

All Claws Mail users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=mail-client/claws-mail-3.17.6"
CVE-2020-15917 sam_c sam_c