CVE-2020-15685 Information
Dec 23, 2022
cve
Description
During the plaintext phase of the STARTTLS connection setup protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7.
Reference
https://bugzilla.mozilla.org/show_bug.cgi?id=1622640 https://www.mozilla.org/security/advisories/mfsa2021-05/
Share on: