CVE-2020-15646 PUBLISHED

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.

EPSS 0.25% · 48.5th percentile

Risk Scores

EPSS Score
0.25%
48.5th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSthunderbird0, 1:68.8.0+build2-0ubuntu0.20.04.2, 1:68.7.0+build1-0ubuntu2
Ubuntu:18.04:LTSthunderbird1:60.5.1+build2-0ubuntu0.18.04.1, 0, 1:52.4.0+build1-0ubuntu2
Ubuntu:16.04:LTSthunderbird1:38.7.2+build1-0ubuntu0.16.04.1, 1:38.6.0+build1-0ubuntu1, 1:38.5.1+build2-0ubuntu1

Timeline

References

Open in Interactive Console →