When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable. This vulnerability affects Thunderbird < 78.5.1.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade thunderbird | Aug 22, 2024 | Dec 9, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 9, 2020 |
| Centos_linux | — | Upgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbird | Dec 15, 2020 | Dec 9, 2020 |
| Debian | — | Upgrade thunderbird | Dec 7, 2020 | Dec 7, 2020 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin. | Dec 7, 2020 | Dec 7, 2020 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 78.5.1 | Dec 2, 2020 | Dec 1, 2020 |
| Oracle Solaris | — | Upgrade mail/thunderbird to version 78.5.1-11.4.29.0.1.82.2 on Solaris 11.4 | Jan 19, 2021 | Dec 9, 2020 |
| Oracle_linux | — | Upgrade thunderbird | Dec 15, 2020 | Dec 1, 2020 |
| Redhat_linux | — | Upgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceNo solution exists | Dec 15, 2020 | Dec 9, 2020 |
| Suse | — | Upgrade mozillathunderbird-translations-otherUpgrade mozillathunderbird-translations-commonUpgrade mozillathunderbird | Jun 2, 2021 | Dec 7, 2020 |
| Ubuntu | — | Upgrade thunderbird | Jan 21, 2021 | Dec 9, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub