{"id":"MGASA-2020-0450","summary":"Updated thunderbird packages fix security vulnerability","details":"When reading SMTP server status codes, Thunderbird writes an integer value to a\nposition on the stack that is intended to contain just one byte. Depending on\nprocessor architecture and stack layout, this leads to stack corruption that\nmay be exploitable (CVE-2020-26970).\n","modified":"2026-04-16T00:12:09.448183485Z","published":"2020-12-05T19:46:49Z","upstream":["CVE-2020-26970"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0450.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=27707"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2020-53/"},{"type":"WEB","url":"https://www.thunderbird.net/en-US/thunderbird/78.5.1/releasenotes/"}],"affected":[{"package":{"name":"thunderbird","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"78.5.1-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0450.json"}},{"package":{"name":"thunderbird-l10n","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"78.5.1-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0450.json"}},{"package":{"name":"rootcerts","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/rootcerts?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20201201.00-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0450.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}