Multiple security issues were discovered in Thunderbird. If a user were tricked in to opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, or execute arbitrary code. (CVE-2020-6831, CVE-2020-12387, CVE-2020-12395)
It was discovered that the Devtools’ ‘Copy as cURL’ feature did not properly escape the HTTP POST data of a request. If a user were tricked in to using the ‘Copy as cURL’ feature to copy and paste a command with specially crafted data in to a terminal, an attacker could potentially exploit this to obtain sensitive information from local files. (CVE-2020-12392)
It was discovered that Thunderbird did not correctly handle Unicode whitespace characters within the From email header. An attacker could potentially exploit this to spoof the sender email address that Thunderbird displays. (CVE-2020-12397)
{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "thunderbird",
            "binary_version": "1:68.8.0+build2-0ubuntu0.16.04.2"
        },
        {
            "binary_name": "thunderbird-dev",
            "binary_version": "1:68.8.0+build2-0ubuntu0.16.04.2"
        },
        {
            "binary_name": "thunderbird-gnome-support",
            "binary_version": "1:68.8.0+build2-0ubuntu0.16.04.2"
        },
        {
            "binary_name": "thunderbird-mozsymbols",
            "binary_version": "1:68.8.0+build2-0ubuntu0.16.04.2"
        },
        {
            "binary_name": "xul-ext-calendar-timezones",
            "binary_version": "1:68.8.0+build2-0ubuntu0.16.04.2"
        },
        {
            "binary_name": "xul-ext-gdata-provider",
            "binary_version": "1:68.8.0+build2-0ubuntu0.16.04.2"
        },
        {
            "binary_name": "xul-ext-lightning",
            "binary_version": "1:68.8.0+build2-0ubuntu0.16.04.2"
        }
    ]
}
          {
    "ecosystem": "Ubuntu:16.04:LTS",
    "cves": [
        {
            "id": "CVE-2020-6831",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2020-12387",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2020-12392",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2020-12395",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2020-12397",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ]
        }
    ]
}
                {
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "thunderbird",
            "binary_version": "1:68.8.0+build2-0ubuntu0.18.04.2"
        },
        {
            "binary_name": "thunderbird-dev",
            "binary_version": "1:68.8.0+build2-0ubuntu0.18.04.2"
        },
        {
            "binary_name": "thunderbird-gnome-support",
            "binary_version": "1:68.8.0+build2-0ubuntu0.18.04.2"
        },
        {
            "binary_name": "thunderbird-mozsymbols",
            "binary_version": "1:68.8.0+build2-0ubuntu0.18.04.2"
        },
        {
            "binary_name": "xul-ext-calendar-timezones",
            "binary_version": "1:68.8.0+build2-0ubuntu0.18.04.2"
        },
        {
            "binary_name": "xul-ext-gdata-provider",
            "binary_version": "1:68.8.0+build2-0ubuntu0.18.04.2"
        },
        {
            "binary_name": "xul-ext-lightning",
            "binary_version": "1:68.8.0+build2-0ubuntu0.18.04.2"
        }
    ]
}
          {
    "ecosystem": "Ubuntu:18.04:LTS",
    "cves": [
        {
            "id": "CVE-2020-6831",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2020-12387",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2020-12392",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2020-12395",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2020-12397",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ]
        }
    ]
}
                {
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "thunderbird",
            "binary_version": "1:68.8.0+build2-0ubuntu0.20.04.2"
        },
        {
            "binary_name": "thunderbird-dev",
            "binary_version": "1:68.8.0+build2-0ubuntu0.20.04.2"
        },
        {
            "binary_name": "thunderbird-gnome-support",
            "binary_version": "1:68.8.0+build2-0ubuntu0.20.04.2"
        },
        {
            "binary_name": "thunderbird-mozsymbols",
            "binary_version": "1:68.8.0+build2-0ubuntu0.20.04.2"
        },
        {
            "binary_name": "xul-ext-calendar-timezones",
            "binary_version": "1:68.8.0+build2-0ubuntu0.20.04.2"
        },
        {
            "binary_name": "xul-ext-gdata-provider",
            "binary_version": "1:68.8.0+build2-0ubuntu0.20.04.2"
        },
        {
            "binary_name": "xul-ext-lightning",
            "binary_version": "1:68.8.0+build2-0ubuntu0.20.04.2"
        }
    ]
}
          {
    "ecosystem": "Ubuntu:20.04:LTS",
    "cves": [
        {
            "id": "CVE-2020-6831",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2020-12387",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2020-12392",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2020-12395",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2020-12397",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ]
        }
    ]
}