{"id":"MGASA-2016-0008","summary":"Updated claws-mail packages fix security vulnerability","details":"no bounds checking on the output buffer in conv_jistoeuc, conv_euctojis,\nconv_sjistoeuc\n\nA Tails contributor found a vulnerability in claws-mail where in\ncodeconv.c a function for japanese character set conversion called\nconv_jistoeuc() has no bounds checking on the output buffer which is\ncreated on the stack with alloca() (CVE-2015-8614).\n","modified":"2026-04-16T06:23:03.286933423Z","published":"2016-01-12T09:13:53Z","upstream":["CVE-2015-8614"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0008.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17380"},{"type":"REPORT","url":"http://www.thewildbeast.co.uk/claws-mail/bugzilla/show_bug.cgi?id=3557"},{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2015-8614"}],"affected":[{"package":{"name":"claws-mail","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/claws-mail?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.11.1-3.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0008.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}