Advisories ยป MGASA-2020-0450

Updated thunderbird packages fix security vulnerability

Publication date: 05 Dec 2020
Modification date: 05 Dec 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-26970

Description

When reading SMTP server status codes, Thunderbird writes an integer value to a
position on the stack that is intended to contain just one byte. Depending on
processor architecture and stack layout, this leads to stack corruption that
may be exploitable (CVE-2020-26970).
                

References

SRPMS

7/core