CVE-2020-26970
high
CVSS v3
—
CVSS v2
—
VIR risk
8.0
Description
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable. This vulnerability affects Thunderbird < 78.5.1.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-26970
Vendor advisory: arch — https://security.archlinux.org/ASA-202012-23
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 78.6.0-1 | |
| debian | bookworm | fixed | 1:78.5.1-1 |
| debian | bullseye | fixed | 1:78.5.1-1 |
| debian | forky | fixed | 1:78.5.1-1 |
| debian | sid | fixed | 1:78.5.1-1 |
| debian | trixie | fixed | 1:78.5.1-1 |
References
Verify integrity in audit chain (admin only). AS-IS.