CVE-2020-6792

説明

CVE.org より

When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 68.5.

CVSS (Common Vulnerability Scoring System) のスコアの詳細

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 スコアの内訳

Red HatNVDcve.org
ベーススコア4.34.3N/A
攻撃ベクトルNetworkNetworkN/A
攻撃の複雑さLowLowN/A
必要な権限NoneNoneN/A
ユーザー関与レベルRequiredRequiredN/A
範囲UnchangedUnchangedN/A
機密性LowLowN/A
完全性への影響NoneNoneN/A
可用性への影響NoneNoneN/A

ベクトル

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

脆弱性の原因 (CWE) の理解

Integrity,Other

Technical Impact: Unexpected State; Quality Degradation; Varies by Context

The uninitialized data may be invalid, causing logic errors within the program. In some cases, this could result in a security problem.

謝辞

Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Chiaki ISHIKAWA as the original reporter.

よくある質問

エラータ通知の受信を希望しますか? こちらで登録してください