RHSA-2020:0919HighCVSS 9.8
Red Hat Security Advisory: thunderbird security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2019-20503 — usrsctp: Out of bounds reads in sctp_load_addresses_from_init() CVE-2020-6805 — Mozilla: Use-after-free when removing data about origins CVE-2020-6806 — Mozilla: BodyStream:: OnInputStreamReady was missing protections against state confusion CVE-2020-6807 — Mozilla: Use-after-free in cubeb during stream destruction CVE-2020-6811 — Mozilla: Devtools' 'Copy as cURL' feature did not fully escape website-controlled data, potentially leading to command injection CVE-2020-6812 — Mozilla: The names of AirPods with personally identifiable information were exposed to websites with camera or microphone permission CVE-2020-6814 — Mozilla: Memory safety bugs fixed in Firefox 74 and Firefox ESR 68.6
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2020:0919
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1812199
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1812200
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1812201
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1812202
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1812203
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1812204
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1812205
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_0919.json