CVE-2020-26966: Medium severity thunderbird vulnerability
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Other sources
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak.Note: This issue only affected Windows operating systems. Other operating systems are unaffected.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-26966?
CVE-2020-26966 is a vulnerability that affects Windows operating systems and allows for an information leak when searching for a single word from the address bar in Mozilla Firefox and Thunderbird.
Which operating systems are affected by CVE-2020-26966?
Only Windows operating systems are affected by CVE-2020-26966.
Which software versions are affected by CVE-2020-26966?
Mozilla Firefox ESR versions up to 78.5, Mozilla Thunderbird up to 78.5, and Mozilla Firefox up to version 83.0 are affected by CVE-2020-26966.
What is the severity of CVE-2020-26966?
CVE-2020-26966 has a severity rating of 6.5 (Medium).
How can I fix CVE-2020-26966?
To mitigate the vulnerability, update Mozilla Firefox ESR to version 78.5, Mozilla Thunderbird to version 78.5, and Mozilla Firefox to version 83.0 or later.