CVE-2020-26973: High severity thunderbird vulnerability
Published Dec 15, 2020
·Updated
Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass.
Affected Software
6 affected componentsFixes available
Mozilla Thunderbird<78.6
78.6
Mozilla Firefox<84.0
Mozilla Firefox ESR<78.6.0
Mozilla Thunderbird<78.6.0
Mozilla Firefox<84
84
Mozilla Firefox ESR<78.6
78.6
Event History
Dec 15, 2020
CVE Published
via Mozilla·12:00 AM
Jan 7, 2021
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
DescriptionWeakness
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2020-26973?
The severity of CVE-2020-26973 is categorized as moderate.
2
How do I fix CVE-2020-26973?
To fix CVE-2020-26973, update to Mozilla Firefox version 85 or later.
3
Which versions of Mozilla software are affected by CVE-2020-26973?
CVE-2020-26973 affects Mozilla Firefox versions prior to 85, Firefox ESR versions prior to 78.6, and Thunderbird versions prior to 78.6.
4
Can CVE-2020-26973 be exploited remotely?
Yes, CVE-2020-26973 can potentially be exploited remotely through crafted input.
5
What is the nature of the vulnerability in CVE-2020-26973?
CVE-2020-26973 is a sanitizer bypass vulnerability that confuses the CSS Sanitizer, leading to incorrect components being removed.