CVE-2020-6793: Medium severity Mozilla Thunderbird vulnerability
Last updated 24 July 2024
Other sources
When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 68.5 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:128.10.0esr-1~deb11u1Fixed in 1:128.8.0esr-1~deb12u1Fixed in 1:128.10.0esr-1~deb12u1Fixed in 1:128.9.0esr-1Fixed in 1:128.10.0esr-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this Thunderbird vulnerability?
The vulnerability ID for this Thunderbird vulnerability is CVE-2020-6793.
What is the severity level of CVE-2020-6793?
The severity level of CVE-2020-6793 is medium with a CVSS score of 6.5.
Which software is affected by CVE-2020-6793?
Thunderbird versions up to 68.5, Debian Thunderbird packages versions 1:91.12.0-1~deb10u1, 1:115.3.1-1~deb10u1, 1:102.13.1-1~deb11u1, 1:115.3.1-1~deb11u1, 1:102.15.1-1~deb12u1, 1:115.3.1-1~deb12u1, 1:115.3.1-1, Ubuntu Thunderbird packages versions 1:68.7.0+ for Bionic, Eoan, and Xenial, and Thunderbird version 68.5.0 from upstream are affected by CVE-2020-6793.
How can I fix CVE-2020-6793?
To fix CVE-2020-6793, update Thunderbird to version 68.6 or later.
Where can I find more information about CVE-2020-6793?
You can find more information about CVE-2020-6793 in the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1608539), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2020-07/), [Gentoo GLSA](https://security.gentoo.org/glsa/202003-10).