CVE-2020-15917: Claws-Mail

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.

Affected products

  • Claws-Mail Claws-Mail: before 3.17.6 (fixed in 3.17.6)
  • Fedoraproject Fedora: version 31 only; version 32 only
  • Opensuse Backports Sle: version 15.0 only
  • Opensuse Leap: version 15.1 only; version 15.2 only

Published 2020-07-23. Last modified 2026-06-17.