Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-12398

Опубликовано: 09 июл. 2020
Источник: debian
EPSS Низкий

Описание

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
thunderbirdfixed1:68.9.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-22/#CVE-2020-12398

EPSS

Процентиль: 49%
0.00262
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.

CVSS3: 7.5
redhat
больше 5 лет назад

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.

CVSS3: 7.5
nvd
больше 5 лет назад

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.

github
больше 3 лет назад

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.

suse-cvrf
больше 5 лет назад

Security update for MozillaThunderbird

EPSS

Процентиль: 49%
0.00262
Низкий