In imap_scan_tree_recursive in Claws Mail through 3.17.6,...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Jul 28, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 29, 2023
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.
References