Gentoo Linux Security Advisory GLSA 200612-06 – It has been identified that Mozilla Thunderbird improperly handles Script objects while they are being executed, allowing them to be modified during execution. JavaScript is disabled in Mozilla Thunderbird by default. Mozilla Thunderbird has also been found to be vulnerable to various potential buffer overflows. Lastly, the binary release of Mozilla Thunderbird is vulnerable to a low exponent RSA signature forgery issue because it is bundled with a vulnerable version of NSS. Versions less than 1.5.0.8 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/52925/glsa-200612-06.txt
Source: https://packetstormsecurity.com/files/52925/Gentoo-Linux-Security-Advisory-200612-6.html

