CVE-2021-37746

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.

References

https://sylpheed.sraoss.jp/sylpheed/v3.7/sylpheed-3.7.0.tar.xz

https://git.claws-mail.org/?p=claws.git;a=commit;h=ac286a71ed78429e16c612161251b9ea90ccd431

https://claws-mail.org/download.php?file=releases/claws-mail-3.18.0.tar.xz

https://lists.fedoraproject.org/archives/list/[email protected]/message/RCJXHUSYHGVBSH2ULD7HNXLM7QNRECZ6/

https://lists.fedoraproject.org/archives/list/[email protected]/message/L2QNUIWASJLPUZZKWICGCEGYJZCQE7NH/

Details

Source: MITRE

Published: 2021-07-30

Updated: 2021-09-20

Type: CWE-601

Risk Information

CVSS v2

Base Score: 5.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Impact Score: 4.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 6.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Impact Score: 2.7

Exploitability Score: 2.8

Severity: MEDIUM