CVE-2020-26970: Critical severity thunderbird vulnerability
Published Dec 1, 2020
·Updated
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable.
Affected Software
2 affected componentsFixes available
Mozilla Thunderbird<78.5.1
78.5.1
Mozilla Thunderbird<78.5.1
Event History
Dec 1, 2020
CVE Published
12:00 AM
Dec 9, 2020
CVE Published
via MITRE·12:26 AM
Data Sourced
via MITRE·12:26 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-26970?
The CVE-2020-26970 vulnerability has a medium severity rating due to potential stack corruption and exploitation risks.
2
How do I fix CVE-2020-26970?
To fix CVE-2020-26970, users should upgrade Thunderbird to version 78.5.1 or later.
3
What versions of Thunderbird are affected by CVE-2020-26970?
CVE-2020-26970 affects all versions of Thunderbird prior to 78.5.1.
4
Is CVE-2020-26970 exploitable?
Yes, CVE-2020-26970 can lead to stack corruption that may be exploited, depending on the processor architecture and stack layout.
5
Who is the vendor responsible for CVE-2020-26970?
The vendor responsible for CVE-2020-26970 is Mozilla, the organization behind Thunderbird.