CVE-2020-15646: Medium severity thunderbird vulnerability
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-15646?
CVE-2020-15646 is a vulnerability that allows an attacker to intercept Thunderbird's automatic account setup and steal usernames and passwords.
How does CVE-2020-15646 work?
CVE-2020-15646 occurs when an attacker intercepts Thunderbird's autodiscovery mechanism and sends a crafted response to steal user credentials.
What is the severity of CVE-2020-15646?
CVE-2020-15646 has a severity rating of 5.9, which is considered high.
Which software is affected by CVE-2020-15646?
Mozilla Thunderbird versions up to and excluding 68.10.0 are affected by CVE-2020-15646.
How can I fix CVE-2020-15646?
To fix CVE-2020-15646, you should update Thunderbird to version 68.10 or higher, which contains the necessary security fixes.