Mageia 2020-0450: thunderbird security update
Mageia 2020-0450: thunderbird security update
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable (CVE-2020-26970).
MGASA-2020-0450 - Updated thunderbird packages fix security vulnerability Publication date: 05 Dec 2020 URL: https://advisories.mageia.org/MGASA-2020-0450.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-26970 When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable (CVE-2020-26970). References: - https://bugs.mageia.org/show_bug.cgi?id=27707 - https://www.mozilla.org/en-US/security/advisories/mfsa2020-53/ - https://www.thunderbird.net/en-US/thunderbird/78.5.1/releasenotes/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26970 SRPMS: - 7/core/thunderbird-78.5.1-1.mga7 - 7/core/thunderbird-l10n-78.5.1-1.mga7 - 7/core/rootcerts-20201201.00-1.mga7