Debian Security Advisory
DSA-3452-1 claws-mail -- security update
- Date Reported:
- 23 Jan 2016
- Affected Packages:
- claws-mail
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2015-8614.
- More information:
-
DrWhax
of the Tails project reported that Claws Mail is missing range checks in some text conversion functions. A remote attacker could exploit this to run arbitrary code under the account of a user that receives a message from them using Claws Mail.For the oldstable distribution (wheezy), this problem has been fixed in version 3.8.1-2+deb7u1.
For the stable distribution (jessie), this problem has been fixed in version 3.11.1-3+deb8u1.
We recommend that you upgrade your claws-mail packages.