Security Advisory

CVE-2020-12398

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-07-09 14:45:35
Last updated 2024-08-04 11:56:52
Assigner mozilla
State PUBLISHED

Description

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.