[RHSA-2020:0577] thunderbird security update
Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 68.5.0.
Security Fix(es):
Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800)
Mozilla: Out-of-bounds read when processing certain email messages (CVE-2020-6793)
Mozilla: Setting a master password post-Thunderbird 52 does not delete unencrypted previously stored passwords (CVE-2020-6794)
Mozilla: Crash processing S/MIME messages with multiple signatures (CVE-2020-6795)
Mozilla: Incorrect parsing of template tag could result in JavaScript injection (CVE-2020-6798)
Mozilla: Message ID calculation was based on uninitialized data (CVE-2020-6792)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/redhat/thunderbird?arch=x86_64&distro=redhat-8.1 | < 68.5.0-1.el8_1 |
pkg:rpm/redhat/thunderbird?arch=ppc64le&distro=redhat-8.1 | < 68.5.0-1.el8_1 |
- ID
- RHSA-2020:0577
- Severity
- important
- URL
- https://access.redhat.com/errata/RHSA-2020:0577
- Published
-
2020-02-24T00:00:00
(4 years ago) - Modified
-
2020-02-24T00:00:00
(4 years ago) - Rights
- Copyright 2020 Red Hat, Inc.
- Other Advisories
-
- ALAS2-2020-1408
- ALPINE:CVE-2020-6792
- ALPINE:CVE-2020-6793
- ALPINE:CVE-2020-6794
- ALPINE:CVE-2020-6795
- ALPINE:CVE-2020-6798
- ALPINE:CVE-2020-6800
- ASA-202002-5
- ASA-202002-9
- DSA-4620-1
- DSA-4625-1
- ELSA-2020-0512
- ELSA-2020-0520
- ELSA-2020-0521
- ELSA-2020-0574
- ELSA-2020-0576
- ELSA-2020-0577
- GLSA-202003-02
- GLSA-202003-10
- MFSA-2020-05
- MFSA-2020-06
- MFSA-2020-07
- openSUSE-SU-2020:0230-1
- openSUSE-SU-2020:0231-1
- RHSA-2020:0512
- RHSA-2020:0520
- RHSA-2020:0521
- RHSA-2020:0574
- RHSA-2020:0576
- SSA:2020-042-01
- SSA:2020-042-02
- SUSE-SU-2020:0383-1
- SUSE-SU-2020:0384-1
- SUSE-SU-2020:0385-1
- USN-4278-1
- USN-4278-2
- USN-4328-1
- USN-4335-1
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 1801918 | https://bugzilla.redhat.com/1801918 | |
Bugzilla | 1801920 | https://bugzilla.redhat.com/1801920 | |
Bugzilla | 1801955 | https://bugzilla.redhat.com/1801955 | |
Bugzilla | 1801956 | https://bugzilla.redhat.com/1801956 | |
Bugzilla | 1801957 | https://bugzilla.redhat.com/1801957 | |
Bugzilla | 1801958 | https://bugzilla.redhat.com/1801958 | |
RHSA | RHSA-2020:0577 | https://access.redhat.com/errata/RHSA-2020:0577 | |
CVE | CVE-2020-6792 | https://access.redhat.com/security/cve/CVE-2020-6792 | |
CVE | CVE-2020-6793 | https://access.redhat.com/security/cve/CVE-2020-6793 | |
CVE | CVE-2020-6794 | https://access.redhat.com/security/cve/CVE-2020-6794 | |
CVE | CVE-2020-6795 | https://access.redhat.com/security/cve/CVE-2020-6795 | |
CVE | CVE-2020-6798 | https://access.redhat.com/security/cve/CVE-2020-6798 | |
CVE | CVE-2020-6800 | https://access.redhat.com/security/cve/CVE-2020-6800 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/thunderbird?arch=x86_64&distro=redhat-8.1 | redhat | thunderbird | < 68.5.0-1.el8_1 | redhat-8.1 | x86_64 | |
Affected | pkg:rpm/redhat/thunderbird?arch=ppc64le&distro=redhat-8.1 | redhat | thunderbird | < 68.5.0-1.el8_1 | redhat-8.1 | ppc64le |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |