Opened 6 years ago
Closed 6 years ago
#14506 closed enhancement (fixed)
thunderbird-78.6.1
| Reported by: | Douglas R. Reno | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 10.1 |
| Component: | BOOK | Version: | SVN |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version
Change History (3)
comment:1 by , 6 years ago
| Priority: | normal → high |
|---|
comment:2 by , 6 years ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
Note:
See TracTickets
for help on using tickets.

For the security fixes:
Mozilla Foundation Security Advisory 2021-02 Security Vulnerabilities fixed in Thunderbird 78.6.1 Announced January 11, 2021 Impact critical Products Thunderbird Fixed in Thunderbird 78.6.1 In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts. #CVE-2020-16044: Use-after-free write when handling a malicious COOKIE-ECHO SCTP chunk Reporter Ned Williamson Impact critical Description A malicious peer could have modified a COOKIE-ECHO chunk in a SCTP packet in a way that potentially resulted in a use-after-free. We presume that with enough effort it could have been exploited to run arbitrary code. References Bug 1683964