Balsa GNOME Balsa

Do you want an email whenever new security vulnerabilities are reported in GNOME Balsa?

By the Year

In 2024 there have been 0 vulnerabilities in GNOME Balsa . Balsa did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 2 7.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Balsa vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent GNOME Balsa Security Vulnerabilities

In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle

CVE-2020-16118 7.5 - High - July 29, 2020

In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.

NULL Pointer Dereference

In GNOME glib-networking through 2.64.2

CVE-2020-13645 6.5 - Medium - May 28, 2020

In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.

Improper Certificate Validation

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Broadcom Fabric Operating System or by GNOME? Click the Watch button to subscribe.

GNOME
Vendor

GNOME Balsa
Product

subscribe