no bounds checking on the output buffer in convjistoeuc, conveuctojis, conv_sjistoeuc
A Tails contributor found a vulnerability in claws-mail where in codeconv.c a function for japanese character set conversion called conv_jistoeuc() has no bounds checking on the output buffer which is created on the stack with alloca() (CVE-2015-8614).