CVE-2020-15917: Claws-Mail
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
Affected products
- Claws-Mail Claws-Mail: before 3.17.6 (fixed in 3.17.6)
- Fedoraproject Fedora: version 31 only; version 32 only
- Opensuse Backports Sle: version 15.0 only
- Opensuse Leap: version 15.1 only; version 15.2 only
Published 2020-07-23. Last modified 2026-06-17.