In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imapmboxconnect in libbalsa/imap/imap-handle.c.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "15.0-sp1"
},
{
"last_affected": "15.0-sp1"
}
],
"vendor_product": "opensuse:backports_sle"
},
{
"cpes": [
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "15.1"
},
{
"last_affected": "15.1"
}
],
"vendor_product": "opensuse:leap"
}
]
}{
"cpe": "cpe:2.3:a:gnome:balsa:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.6.0"
}
]
}"2026-07-09T00:21:19Z"
[
{
"signature_type": "Function",
"target": {
"file": "libbalsa/imap/imap-handle.c",
"function": "ir_preauth"
},
"deprecated": false,
"source": "https://gitlab.gnome.org/gnome/balsa@4e245d758e1c826a01080d40c22ca8706f0339e5",
"id": "CVE-2020-16118-65473ce8",
"signature_version": "v1",
"digest": {
"function_hash": "31836230078113631678238411961133440548",
"length": 145.0
}
},
{
"signature_type": "Function",
"target": {
"file": "libbalsa/imap/imap-handle.c",
"function": "imap_mbox_connect"
},
"deprecated": false,
"source": "https://gitlab.gnome.org/gnome/balsa@4e245d758e1c826a01080d40c22ca8706f0339e5",
"id": "CVE-2020-16118-b2320216",
"signature_version": "v1",
"digest": {
"function_hash": "293968677701453279845062206111635714870",
"length": 1964.0
}
},
{
"signature_type": "Line",
"target": {
"file": "libbalsa/imap/imap-handle.c"
},
"deprecated": false,
"source": "https://gitlab.gnome.org/gnome/balsa@4e245d758e1c826a01080d40c22ca8706f0339e5",
"id": "CVE-2020-16118-f4c4f08b",
"signature_version": "v1",
"digest": {
"line_hashes": [
"1643226158156333488970853661134900088",
"228218704177446988173638814297809441413",
"236248795415852436039219694572462381721",
"18478388076030129196173864960940574670",
"23703402067512023341633421662796275974",
"118947903512508494928110480117462030534",
"98931956777700046772554200538121766800",
"238454973838811676910368375657663991330",
"263680398036305298661078886103628345842",
"201554279598316517544620395921944958198"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-16118.json"