When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable. This vulnerability affects Thunderbird < 78.5.1.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-thunderbird | Aug 22, 2024 | Dec 9, 2020 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Dec 9, 2020 | |
| Centos_linux | — | centos-upgrade-thunderbirdcentos-upgrade-thunderbird-debuginfocentos-upgrade-thunderbird-debugsource | Dec 15, 2020 | Dec 9, 2020 |
| Debian | debian-upgrade-thunderbird | Dec 7, 2020 | Dec 7, 2020 | |
| Gentoo Linux | gentoo-linux-upgrade-mail-client-thunderbirdgentoo-linux-upgrade-mail-client-thunderbird-bin | Dec 7, 2020 | Dec 7, 2020 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-78_5_1 | Dec 2, 2020 | Dec 1, 2020 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-mail-thunderbird-78-5-1-11-4-29-0-1-82-2 | Jan 19, 2021 | Dec 9, 2020 | |
| Oracle_linux | — | oracle-linux-upgrade-thunderbird | Dec 15, 2020 | Dec 1, 2020 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-thunderbirdredhat-upgrade-thunderbird-debuginforedhat-upgrade-thunderbird-debugsource | Dec 15, 2020 | Dec 9, 2020 | |
| Suse | — | suse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Jun 2, 2021 | Dec 7, 2020 |
| Ubuntu | ubuntu-upgrade-thunderbird | Jan 21, 2021 | Dec 9, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub