CVE-2020-15685: Command Injection
Published Jan 26, 2021
·Updated
During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session.
Affected Software
3 affected componentsFixes available
debian/thunderbird
1:91.12.0-1~deb10u11:115.3.1-1~deb10u11:102.13.1-1~deb11u11:115.3.1-1~deb11u11:102.15.1-1~deb12u11:115.3.1-1~deb12u11:115.3.1-1
Mozilla Thunderbird<78.7
78.7
Mozilla Thunderbird<78.7.0
Remediation
Patch Available
Event History
Jan 26, 2021
CVE Published
12:00 AM
Dec 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2020-15685?
CVE-2020-15685 has a medium severity level due to potential command injection vulnerabilities during the STARTTLS setup.
2
How do I fix CVE-2020-15685?
To fix CVE-2020-15685, upgrade to versions of Thunderbird that are not affected, specifically 78.7.0 or later.
3
Which versions of Thunderbird are affected by CVE-2020-15685?
CVE-2020-15685 affects Thunderbird versions prior to 78.7.0.
4
What type of vulnerability is CVE-2020-15685?
CVE-2020-15685 is a command injection vulnerability during the plaintext phase of the STARTTLS connection.
5
Is CVE-2020-15685 specific to any particular operating system?
CVE-2020-15685 primarily affects the Mozilla Thunderbird email client across various operating systems.