VDB

GCVE-110-MAGEIA-2020-450

GCVE-110-MAGEIA-2020-450
Advisory Published
Vulnetix · Advisory published December 5, 2020
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable (CVE-2020-26970).

Affected Products

VendorProductVersionsPlatforms
Mageiarootcerts0 (affected), 20201201.00-1.mga7 (unaffected)
Mageiathunderbird-l10n0 (affected), 78.5.1-1.mga7 (unaffected)
Mageiathunderbird0 (affected), 78.5.1-1.mga7 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›