CVE-2020-6795: Null Pointer Dereference
Last updated 24 July 2024
Other sources
When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to an unexploitable crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 68.5 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:128.10.0esr-1~deb11u1Fixed in 1:128.8.0esr-1~deb12u1Fixed in 1:128.10.0esr-1~deb12u1Fixed in 1:128.9.0esr-1Fixed in 1:128.10.0esr-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-6795?
CVE-2020-6795 is a vulnerability in Thunderbird, which could cause a null pointer dereference leading to a crash.
How does CVE-2020-6795 affect Thunderbird?
CVE-2020-6795 affects Thunderbird versions up to 68.5.
What is the severity of CVE-2020-6795?
CVE-2020-6795 has a severity rating of 6.5, which is considered medium.
How can I fix CVE-2020-6795 in Thunderbird?
To fix CVE-2020-6795 in Thunderbird, update to version 68.7.0 or newer.
Where can I find more information about CVE-2020-6795?
You can find more information about CVE-2020-6795 in the following references: [https://bugzilla.mozilla.org/show_bug.cgi?id=1611105](https://bugzilla.mozilla.org/show_bug.cgi?id=1611105), [https://security.gentoo.org/glsa/202003-10](https://security.gentoo.org/glsa/202003-10), [https://usn.ubuntu.com/4328-1/](https://usn.ubuntu.com/4328-1/).