common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
No PoCs from references.
- https://github.com/Live-Hack-CVE/CVE-2020-15917