CVE-2020-12425: Medium severity thunderbird vulnerability
Published Jun 30, 2020
·Updated
Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information disclosure.
Affected Software
4 affected componentsFixes available
Mozilla Thunderbird<78
78
Mozilla Firefox<78
78
Mozilla Firefox<78.0
debian/firefox
137.0.2-1
Event History
Jun 30, 2020
CVE Published
12:00 AM
Jul 9, 2020
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:38 PM
Description
Sep 24, 2024
Data Sourced
via Ubuntu·01:18 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·03:38 AM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-12425.
2
What software products are affected by this vulnerability?
Mozilla Firefox version up to 78 and Mozilla Thunderbird version up to 78 are affected by this vulnerability.
3
What is the severity of CVE-2020-12425?
The severity of CVE-2020-12425 is low.
4
What is the potential impact of this vulnerability?
This vulnerability could lead to potential information disclosure.
5
How can I fix CVE-2020-12425?
To fix CVE-2020-12425, update to a version of Mozilla Firefox or Mozilla Thunderbird that is higher than 78.