VulnerabilityModified
CVE-2020-6792
This vulnerability affects Thunderbird < 68.5.
MEDIUM 4.3EPSS 1.33%
Does this matter?
Lower severity and a low EPSS score (1.33%). Track it; it rarely justifies an emergency change on its own.
Description
When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 68.5.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 1.33% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-908, CWE-909
- Affected
- mozilla/thunderbird · canonical/ubuntu linux
- Source
- security@mozilla.org
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1609607Issue Tracking, Permissions Required
- https://security.gentoo.org/glsa/202003-10Third Party Advisory
- https://usn.ubuntu.com/4328-1/Third Party Advisory
- https://usn.ubuntu.com/4335-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-07/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1609607Issue Tracking, Permissions Required
- https://security.gentoo.org/glsa/202003-10Third Party Advisory
- https://usn.ubuntu.com/4328-1/Third Party Advisory
- https://usn.ubuntu.com/4335-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-07/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.