Out-of-bounds read in Mozilla Thunderbird - CVE-2020-6793
Published: February 11, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when processing email messages. A remote attacker can send a specially crafted email message to the victim, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system or crash the application.
Affected software
Arch Linux
Gentoo Linux
CentOS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
thunderbird (Debian package)
thunderbird (Ubuntu package)
thunderbird (Alpine package)
How to mitigate CVE-2020-6793
thunderbird (Debian package) - addressed in versions 1:68.5.0-1~deb9u1, 1:68.5.0-1~deb10u1
thunderbird (Ubuntu package) - update to 1:68.7.0+build1-0ubuntu0.16.04.2
thunderbird (Alpine package) - update to 68.5.0-r0
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Thunderbird
- Slackware Linux update for mozilla-thunderbird
- Arch Linux update for thunderbird
- Debian update for thunderbird
- OpenSUSE Linux update for MozillaThunderbird
- Red Hat update for thunderbird
- Red Hat update for thunderbird
- Red Hat update for thunderbird
- Red Hat update for thunderbird
- Gentoo update for Mozilla Thunderbird
- CentOS 7 update for thunderbird
- CentOS 6 update for thunderbird
- Ubuntu update for Thunderbird
- Out-of-bounds read in thunderbird (Alpine package)