Debian Security Advisory
DLA-2408-1 thunderbird -- LTS security update
- Date Reported:
- 17 Oct 2020
- Affected Packages:
- thunderbird
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2020-15673, CVE-2020-15676, CVE-2020-15677, CVE-2020-15678.
- More information:
-
Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service.
Debian follows the Thunderbird upstream releases. Support for the 68.x series has ended, so starting with this update we're now following the 78.x releases.
The 78.x series discontinues support for some addons. Also, starting with 78, Thunderbird supports OpenPGP natively. If you are currently using the Enigmail addon for PGP, please refer to the included NEWS and README.Debian.gz files for information on how to migrate your keys.
For Debian 9 stretch, these problems have been fixed in version 1:78.3.1-2~deb9u1.
We recommend that you upgrade your thunderbird packages.
For the detailed security status of thunderbird please refer to its security tracker page at: https://security-tracker.debian.org/tracker/thunderbird
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS