
====================================================================

                             CERT-Renater

                 Note d'Information No. 2020/VULN596
_____________________________________________________________________

DATE                : 22/10/2020

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Windows running Mozilla Thunderbird versions
                                   prior to 78.4.

=====================================================================
https://www.mozilla.org/en-US/security/advisories/mfsa2020-47/
_____________________________________________________________________


Mozilla Foundation Security Advisory 2020-47
Security Vulnerabilities fixed in Thunderbird 78.4

Announced        October 21, 2020
Impact           high
Products         Thunderbird
Fixed in
        Thunderbird 78.4

In general, these flaws cannot be exploited through email in the
Thunderbird product because scripting is disabled when reading mail, but
are potentially risks in browser or browser-like contexts.


#CVE-2020-15969: Use-after-free in usersctp

Reporter        Mark Wodrich of Google
Impact          high

Description

A use-after-free bug in the usersctp library was reported upstream. We
assume this could have led to memory corruption and a potentially
exploitable crash.

References

    Bug 1666570
    [sctplab] upstream usrsctp fix


#CVE-2020-15683: Memory safety bugs fixed in Thunderbird 78.4

Reporter         Mozilla developers and community
Impact           high

Description

Mozilla developers and community members Jason Kratzer, Simon Giesecke,
Philipp, and Christian Holler reported memory safety bugs present in
Thunderbird 78.3. Some of these bugs showed evidence of memory
corruption and we presume that with enough effort some of these could
have been exploited to run arbitrary code.


References

    Memory safety bugs fixed in Thunderbird 78.4



=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================


