Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11705

Опубликовано: 13 июн. 2019
Источник: redhat
CVSS3: 9.8

Описание

A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.

Меры по смягчению последствий

Thunderbird can be configured to use icaljs instead of libical by setting calendar.icaljs = true in preferences, mitigating this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libicalOut of support scope
Red Hat Enterprise Linux 7libicalNot affected
Red Hat Enterprise Linux 8libicalNot affected
Red Hat Enterprise Linux 6thunderbirdFixedRHSA-2019:162427.06.2019
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2019:162627.06.2019
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2019:162327.06.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1720008libical: Stack buffer overflow in icalrecur_add_bydayrules in icalrecur.c

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.

CVSS3: 9.8
nvd
почти 6 лет назад

A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.

CVSS3: 9.8
debian
почти 6 лет назад

A flaw in Thunderbird's implementation of iCal causes a stack buffer o ...

CVSS3: 9.8
github
около 3 лет назад

A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.

CVSS3: 9.8
fstec
почти 6 лет назад

Уязвимость библиотеки libical почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании

9.8 Critical

CVSS3