Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-12398

Опубликовано: 09 июл. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 7.5

Описание

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.

РелизСтатусПримечание
bionic

released

1:68.10.0+build1-0ubuntu0.18.04.1
devel

released

1:68.9.0+build1-0ubuntu1
eoan

released

1:68.10.0+build1-0ubuntu0.19.10.1
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

released

1:68.10.0+build1-0ubuntu0.20.04.1
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

upstream

released

68.9.0

Показывать по

4.3 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 5 лет назад

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.

CVSS3: 7.5
nvd
больше 5 лет назад

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.

CVSS3: 7.5
debian
больше 5 лет назад

If Thunderbird is configured to use STARTTLS for an IMAP server, and t ...

github
больше 3 лет назад

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.

suse-cvrf
больше 5 лет назад

Security update for MozillaThunderbird

4.3 Medium

CVSS2

7.5 High

CVSS3