Updated thunderbird packages fix security vulnerability
Publication date: 05 Dec 2020Modification date: 05 Dec 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-26970
Description
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable (CVE-2020-26970).
References
SRPMS
7/core
- thunderbird-78.5.1-1.mga7
- thunderbird-l10n-78.5.1-1.mga7
- rootcerts-20201201.00-1.mga7