CVE-2020-26970

Publication date 9 December 2020

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

8.8 · High

Score breakdown

When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable. This vulnerability affects Thunderbird < 78.5.1.

Status

Package Ubuntu Release Status
thunderbird 23.04 lunar
Fixed 1:78.5.1+build1-0ubuntu1
22.10 kinetic
Fixed 1:78.5.1+build1-0ubuntu1
22.04 LTS jammy
Fixed 1:78.5.1+build1-0ubuntu1
21.10 impish
Fixed 1:78.5.1+build1-0ubuntu1
21.04 hirsute
Fixed 1:78.5.1+build1-0ubuntu1
20.10 groovy
Fixed 1:78.6.1+build1-0ubuntu0.20.10.1
20.04 LTS focal
Fixed 1:78.7.1+build1-0ubuntu0.20.04.1
18.04 LTS bionic
Fixed 1:78.8.1+build1-0ubuntu0.18.04.1
16.04 LTS xenial Ignored end of standard support, was needs-triage
14.04 LTS trusty Not in release

Severity score breakdown

Parameter Value
Base score 8.8 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H