[MFSA-2020-53] Security Vulnerabilities fixed in Thunderbird 78.5.1

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1
  • CVE-2020-26970: Stack overflow due to incorrect parsing of SMTP server response codes (high) When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable.
Package Affected Version
pkg:mozilla/Thunderbird < 78.5.1
Package Fixed Version
pkg:mozilla/Thunderbird = 78.5.1
Source # ID Name URL
Bugzilla 1677338 https://bugzilla.mozilla.org/show_bug.cgi?id=1677338
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:mozilla/Thunderbird Thunderbird < 78.5.1
Fixed pkg:mozilla/Thunderbird Thunderbird = 78.5.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...