Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 730628 (MFSA-2020-0001)

Summary: <mail-client/thunderbird{,-bin}-68.10.0: Multiple Vulnerabilities (CVE-2020-{12417,12418,12419,12420,12421}, MSFA-2020-0001)
Product: Gentoo Security Reporter: John Helmert III <ajak>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: major CC: mozilla
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://www.mozilla.org/en-US/security/advisories/mfsa2020-26/
Whiteboard: A2 [glsa+ cve]
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 730626    

Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-07-03 19:31:55 UTC
MSFA-2020-0001 (Pending CVE):

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2020-07-26 23:39:43 UTC
This issue was resolved and addressed in
 GLSA 202007-09 at https://security.gentoo.org/glsa/202007-09
by GLSA coordinator Sam James (sam_c).