Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 730628 (MFSA-2020-0001) - <mail-client/thunderbird{,-bin}-68.10.0: Multiple Vulnerabilities (CVE-2020-{12417,12418,12419,12420,12421}, MSFA-2020-0001)
Summary: <mail-client/thunderbird{,-bin}-68.10.0: Multiple Vulnerabilities (CVE-2020-{...
Status: RESOLVED FIXED
Alias: MFSA-2020-0001
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL: https://www.mozilla.org/en-US/securit...
Whiteboard: A2 [glsa+ cve]
Keywords:
Depends on:
Blocks: CVE-2020-12417, CVE-2020-12418, CVE-2020-12419, CVE-2020-12420, CVE-2020-12421
  Show dependency tree
 
Reported: 2020-07-03 19:31 UTC by John Helmert III
Modified: 2020-07-26 23:39 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-07-03 19:31:55 UTC
MSFA-2020-0001 (Pending CVE):

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2020-07-26 23:39:43 UTC
This issue was resolved and addressed in
 GLSA 202007-09 at https://security.gentoo.org/glsa/202007-09
by GLSA coordinator Sam James (sam_c).