MGASA-2016-0008
Dashboard / Vulnerabilities / MGASA-2016-0008
Summary: Updated claws-mail packages fix security vulnerability
Details: no bounds checking on the output buffer in conv_jistoeuc, conv_euctojis, conv_sjistoeuc A Tails contributor found a vulnerability in claws-mail where in codeconv.c a function for japanese character set conversion called conv_jistoeuc() has no bounds checking on the output buffer which is created on the stack with alloca() (CVE-2015-8614).
References: https://advisories.mageia.org/MGASA-2016-0008.html, https://bugs.mageia.org/show_bug.cgi?id=17380, http://www.thewildbeast.co.uk/claws-mail/bugzilla/show_bug.cgi?id=3557, https://security-tracker.debian.org/tracker/CVE-2015-8614
Affected packages
Package
Name: claws-mail
Purl: pkg:rpm/mageia/claws-mail?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
