FS#68853 - [thunderbird] [Security] arbitrary code execution (CVE-2020-26970)
Attached to Project:
Arch Linux
Opened by Jonathon (jonathon) - Friday, 04 December 2020, 16:56 GMT
Last edited by Levente Polyak (anthraxx) - Tuesday, 15 December 2020, 00:06 GMT
Opened by Jonathon (jonathon) - Friday, 04 December 2020, 16:56 GMT
Last edited by Levente Polyak (anthraxx) - Tuesday, 15 December 2020, 00:06 GMT
|
Details
Summary
======= The package thunderbird is vulnerable to arbitrary code execution via CVE-2020-26970. Affects 78.4.3 (extra) and 78.5.0 (testing). Guidance ======== Fixed in 78.5.1. Will need patch for Rust 1.48 build failures: https://bugs.archlinux.org/task/68825 References ========== https://security.archlinux.org/AVG-1315 https://www.mozilla.org/en-US/security/advisories/mfsa2020-53/ https://www.mozilla.org/en-US/security/advisories/mfsa2020-53/#CVE-2020-26970 https://bugzilla.mozilla.org/show_bug.cgi?id=1677338 |
Closed by Levente Polyak (anthraxx)
Tuesday, 15 December 2020, 00:06 GMT
Reason for closing: Fixed
Additional comments about closing: 78.5.1-1
Tuesday, 15 December 2020, 00:06 GMT
Reason for closing: Fixed
Additional comments about closing: 78.5.1-1