When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability affects Thunderbird < 68.5.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade thunderbird | Aug 22, 2024 | Mar 2, 2020 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Apr 27, 2020 | Mar 2, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 2, 2020 |
| Centos_linux | — | Upgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsource | Feb 25, 2020 | Feb 24, 2020 |
| Debian | — | Upgrade thunderbird | Feb 18, 2020 | Feb 18, 2020 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin. | Mar 16, 2020 | Mar 2, 2020 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 68.5 | Feb 12, 2020 | Feb 11, 2020 |
| Oracle Solaris | — | Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.5.0-11.4.19.0.1.2.0 on Solaris 11.4Upgrade mail/thunderbird to version 68.5.0-11.4.19.0.1.2.0 on Solaris 11.4 | Jan 19, 2021 | Mar 2, 2020 |
| Oracle_linux | — | Upgrade thunderbird | Mar 2, 2020 | Feb 11, 2020 |
| Redhat_linux | — | No solution existsUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbird | Feb 25, 2020 | Feb 24, 2020 |
| Suse | — | Upgrade mozillathunderbird-translations-commonUpgrade mozillathunderbird-translations-otherUpgrade mozillathunderbird | Feb 19, 2020 | Feb 17, 2020 |
| Ubuntu | — | Upgrade thunderbird | Apr 14, 2020 | Feb 17, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub