In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Evolution-data-server | Gnome | * | 3.35.91 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | evolution-0:3.28.5-16.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | evolution-data-server-0:3.28.5-15.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | evolution-ews-0:3.28.5-10.el8 | * |
Evolution-data-server | Ubuntu | bionic | * |
Evolution-data-server | Ubuntu | trusty | * |
Evolution-data-server | Ubuntu | upstream | * |
Evolution-data-server | Ubuntu | xenial | * |