CVE-2020-12397: Canonical Ubuntu Linux

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only; version 20.04 only
  • Mozilla Thunderbird: before 68.8.0 (fixed in 68.8.0)

Published 2020-05-22. Last modified 2026-06-17.