CVE-2020-15685
Summary
| CVE | CVE-2020-15685 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-22 20:15:00 UTC |
| Updated | 2023-01-04 14:14:00 UTC |
| Description | During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Mozilla |
Thunderbird |
All |
All |
All |
All |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296069 Oracle Solaris 11.4 Support Repository Update (SRU) 31.88.5 Missing (CPUJAN2021)
- 502378 Alpine Linux Security Update for thunderbird
- 750379 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:0208-1)
- 750380 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:0209-1)