CVE-2021-37746

Name
CVE-2021-37746
Description
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://sylpheed.sraoss.jp/sylpheed/v3.7/sylpheed-3.7.0.tar.xz
MISC https://git.claws-mail.org/?p=claws.git;a=commit;h=ac286a71ed78429e16c612161251b9ea90ccd431
MISC https://claws-mail.org/download.php?file=releases/claws-mail-3.18.0.tar.xz
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RCJXHUSYHGVBSH2ULD7HNXLM7QNRECZ6/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L2QNUIWASJLPUZZKWICGCEGYJZCQE7NH/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:claws-mail:claws-mail:*:*:*:*:*:*:*:* claws-mail >= None < 3.18.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
claws-mail 3.14-community 3.17.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable