NULL pointer dereference in Debian Linux - CVE-2020-16117

 

NULL pointer dereference in Debian Linux - CVE-2020-16117

Published: July 29, 2020 / Updated: August 21, 2020


Vulnerability identifier: #VU45886
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16117
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server. A remote attacker can perform a denial of service (DoS) attack.


Affected software

Debian Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
openEuler
evolution-ews (Red Hat package)
evolution (Red Hat package)
evolution-data-server (Red Hat package)
libcamel-1_2-57
libcamel-1_2-57-debuginfo
libedataserver-1_2-21
libedataserver-1_2-21-debuginfo
libedataserver-1_2-22-32bit
libecal-1_2-19
libecal-1_2-19-32bit
libecal-1_2-19-debuginfo
libecal-1_2-19-debuginfo-32bit
libedata-book-1_2-25
libedata-book-1_2-25-32bit
libedata-book-1_2-25-debuginfo
libedata-book-1_2-25-debuginfo-32bit
libedata-cal-1_2-28
libedata-cal-1_2-28-32bit
libedata-cal-1_2-28-debuginfo
libedata-cal-1_2-28-debuginfo-32bit
libedataserver-1_2-22
libebook-contacts-1_2-2-32bit
libedataserver-1_2-22-debuginfo
libedataserver-1_2-22-debuginfo-32bit
libedataserverui-1_2-1
libedataserverui-1_2-1-debuginfo
evolution-data-server-lang
evolution-data-server-devel
typelib-1_0-EBook-1_2
typelib-1_0-EBookContacts-1_2
libebackend-1_2-10
typelib-1_0-EDataServer-1_2
evolution-data-server
evolution-data-server-32bit
evolution-data-server-debuginfo
evolution-data-server-debuginfo-32bit
evolution-data-server-debugsource
libcamel-1_2-59
libcamel-1_2-59-32bit
libcamel-1_2-59-debuginfo
libcamel-1_2-59-debuginfo-32bit
libebook-contacts-1_2-2-debuginfo-32bit
libebackend-1_2-10-32bit
libebackend-1_2-10-debuginfo
libebackend-1_2-10-debuginfo-32bit
libebook-1_2-16
libebook-1_2-16-32bit
libebook-1_2-16-debuginfo
libebook-1_2-16-debuginfo-32bit
libebook-contacts-1_2-2
libebook-contacts-1_2-2-debuginfo
evolution-data-server-langpacks
evolution-data-server-perl
evolution-data-server-doc
evolution-ews-lang
typelib-1_0-EDataServerUI-1_2
typelib-1_0-ECal-2_0
typelib-1_0-Camel-1_2
libedataserverui-1_2-2-debuginfo
libedataserverui-1_2-2
libedataserver-1_2-24-debuginfo
libedataserver-1_2-24
libedata-cal-2_0-1
evolution-ews
evolution-ews-debuginfo
evolution-ews-debugsource
libcamel-1_2-62
libcamel-1_2-62-debuginfo
libedata-cal-2_0-1-debuginfo
libebook-1_2-20
libebook-1_2-20-debuginfo
libebook-contacts-1_2-3
libebook-contacts-1_2-3-debuginfo
libecal-2_0-1
libecal-2_0-1-debuginfo
libedata-book-1_2-26
libedata-book-1_2-26-debuginfo

How to mitigate CVE-2020-16117

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

evolution-ews (Red Hat package) - update to 3.28.5-10.el8
evolution (Red Hat package) - update to 3.28.5-16.el8
evolution-data-server (Red Hat package) - update to 3.28.5-15.el8
libcamel-1_2-57 - update to 3.20.6-17.3.1
libcamel-1_2-57-debuginfo - update to 3.20.6-17.3.1
libedataserver-1_2-21 - update to 3.20.6-17.3.1
libedataserver-1_2-21-debuginfo - update to 3.20.6-17.3.1
libedataserver-1_2-22-32bit - update to 3.22.7-18.7.1
libecal-1_2-19 - update to 3.22.7-18.7.1
libecal-1_2-19-32bit - update to 3.22.7-18.7.1
libecal-1_2-19-debuginfo - update to 3.22.7-18.7.1
libecal-1_2-19-debuginfo-32bit - update to 3.22.7-18.7.1
libedata-book-1_2-25 - update to 3.22.7-18.7.1
libedata-book-1_2-25-32bit - update to 3.22.7-18.7.1
libedata-book-1_2-25-debuginfo - update to 3.22.7-18.7.1
libedata-book-1_2-25-debuginfo-32bit - update to 3.22.7-18.7.1
libedata-cal-1_2-28 - update to 3.22.7-18.7.1
libedata-cal-1_2-28-32bit - update to 3.22.7-18.7.1
libedata-cal-1_2-28-debuginfo - update to 3.22.7-18.7.1
libedata-cal-1_2-28-debuginfo-32bit - update to 3.22.7-18.7.1
libedataserver-1_2-22 - update to 3.22.7-18.7.1
libebook-contacts-1_2-2-32bit - update to 3.22.7-18.7.1
libedataserver-1_2-22-debuginfo - update to 3.22.7-18.7.1
libedataserver-1_2-22-debuginfo-32bit - update to 3.22.7-18.7.1
libedataserverui-1_2-1 - update to 3.22.7-18.7.1
libedataserverui-1_2-1-debuginfo - update to 3.22.7-18.7.1
evolution-data-server-lang - addressed in versions 3.22.7-18.7.1, 3.34.4-3.3.1
evolution-data-server-devel - addressed in versions 3.22.7-18.7.1, 3.34.4-3.3.1
typelib-1_0-EBook-1_2 - addressed in versions 3.22.7-18.7.1, 3.34.4-3.3.1
typelib-1_0-EBookContacts-1_2 - addressed in versions 3.22.7-18.7.1, 3.34.4-3.3.1
libebackend-1_2-10 - addressed in versions 3.22.7-18.7.1, 3.34.4-3.3.1
typelib-1_0-EDataServer-1_2 - addressed in versions 3.22.7-18.7.1, 3.34.4-3.3.1
evolution-data-server - addressed in versions 3.22.7-18.7.1, 3.34.4-3.3.1
evolution-data-server-32bit - update to 3.22.7-18.7.1
evolution-data-server-debuginfo - addressed in versions 3.22.7-18.7.1, 3.34.4-3.3.1
evolution-data-server-debuginfo-32bit - update to 3.22.7-18.7.1
evolution-data-server-debugsource - addressed in versions 3.22.7-18.7.1, 3.34.4-3.3.1
libcamel-1_2-59 - update to 3.22.7-18.7.1
libcamel-1_2-59-32bit - update to 3.22.7-18.7.1
libcamel-1_2-59-debuginfo - update to 3.22.7-18.7.1
libcamel-1_2-59-debuginfo-32bit - update to 3.22.7-18.7.1
libebook-contacts-1_2-2-debuginfo-32bit - update to 3.22.7-18.7.1
libebackend-1_2-10-32bit - update to 3.22.7-18.7.1
libebackend-1_2-10-debuginfo - addressed in versions 3.22.7-18.7.1, 3.34.4-3.3.1
libebackend-1_2-10-debuginfo-32bit - update to 3.22.7-18.7.1
libebook-1_2-16 - update to 3.22.7-18.7.1
libebook-1_2-16-32bit - update to 3.22.7-18.7.1
libebook-1_2-16-debuginfo - update to 3.22.7-18.7.1
libebook-1_2-16-debuginfo-32bit - update to 3.22.7-18.7.1
libebook-contacts-1_2-2 - update to 3.22.7-18.7.1
libebook-contacts-1_2-2-debuginfo - update to 3.22.7-18.7.1
evolution-data-server-langpacks - update to 3.30.1-4
evolution-data-server - update to 3.30.1-4
evolution-data-server-debuginfo - update to 3.30.1-4
evolution-data-server-debugsource - update to 3.30.1-4
evolution-data-server-devel - update to 3.30.1-4
evolution-data-server-perl - update to 3.30.1-4
evolution-data-server-doc - update to 3.30.1-4
evolution-ews-lang - update to 3.34.4-3.3.1
typelib-1_0-EDataServerUI-1_2 - update to 3.34.4-3.3.1
typelib-1_0-ECal-2_0 - update to 3.34.4-3.3.1
typelib-1_0-Camel-1_2 - update to 3.34.4-3.3.1
libedataserverui-1_2-2-debuginfo - update to 3.34.4-3.3.1
libedataserverui-1_2-2 - update to 3.34.4-3.3.1
libedataserver-1_2-24-debuginfo - update to 3.34.4-3.3.1
libedataserver-1_2-24 - update to 3.34.4-3.3.1
libedata-cal-2_0-1 - update to 3.34.4-3.3.1
evolution-ews - update to 3.34.4-3.3.1
evolution-ews-debuginfo - update to 3.34.4-3.3.1
evolution-ews-debugsource - update to 3.34.4-3.3.1
libcamel-1_2-62 - update to 3.34.4-3.3.1
libcamel-1_2-62-debuginfo - update to 3.34.4-3.3.1
libedata-cal-2_0-1-debuginfo - update to 3.34.4-3.3.1
libebook-1_2-20 - update to 3.34.4-3.3.1
libebook-1_2-20-debuginfo - update to 3.34.4-3.3.1
libebook-contacts-1_2-3 - update to 3.34.4-3.3.1
libebook-contacts-1_2-3-debuginfo - update to 3.34.4-3.3.1
libecal-2_0-1 - update to 3.34.4-3.3.1
libecal-2_0-1-debuginfo - update to 3.34.4-3.3.1
libedata-book-1_2-26 - update to 3.34.4-3.3.1
libedata-book-1_2-26-debuginfo - update to 3.34.4-3.3.1

External References

Related Security Bulletins