[MFSA-2020-47] Security Vulnerabilities fixed in Thunderbird 78.4

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 2

In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.

  • CVE-2020-15683: Memory safety bugs fixed in Thunderbird 78.4 (high)
    Mozilla developers and community members Jason Kratzer, Simon Giesecke, Philipp, and Christian Holler reported memory safety bugs present in Thunderbird 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.

  • CVE-2020-15969: Use-after-free in usersctp (high)
    A use-after-free bug in the usersctp library was reported upstream. We assume this could have led to memory corruption and a potentially exploitable crash.

Package Affected Version
pkg:mozilla/Thunderbird < 78.4
Package Fixed Version
pkg:mozilla/Thunderbird = 78.4
Source # ID Name URL
Bugzilla 1576843 Memory safety bugs fixed in Thunderbird 78.4 https://bugzilla.mozilla.org/show_bug.cgi?id=1576843
Bugzilla 1656987 Memory safety bugs fixed in Thunderbird 78.4 https://bugzilla.mozilla.org/show_bug.cgi?id=1656987
Bugzilla 1660954 Memory safety bugs fixed in Thunderbird 78.4 https://bugzilla.mozilla.org/show_bug.cgi?id=1660954
Bugzilla 1662760 Memory safety bugs fixed in Thunderbird 78.4 https://bugzilla.mozilla.org/show_bug.cgi?id=1662760
Bugzilla 1663439 Memory safety bugs fixed in Thunderbird 78.4 https://bugzilla.mozilla.org/show_bug.cgi?id=1663439
Bugzilla 1666140 Memory safety bugs fixed in Thunderbird 78.4 https://bugzilla.mozilla.org/show_bug.cgi?id=1666140
Bugzilla 1666570 https://bugzilla.mozilla.org/show_bug.cgi?id=1666570
[sctplab] upstream usrsctp fix https://github.com/sctplab/usrsctp/commit/ffed0925f27d404173c1e3e750d818f432d2c019
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:mozilla/Thunderbird Thunderbird < 78.4
Fixed pkg:mozilla/Thunderbird Thunderbird = 78.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date