Описание
Security update for MozillaThunderbird
This update for MozillaThunderbird fixes the following issues:
Security issues fixed:
- CVE-2019-11703: Fixed a heap-based buffer overflow in icalmemorystrdupanddequote() (bsc#1137595).
- CVE-2019-11704: Fixed a heap-based buffer overflow in parser_get_next_char() (bsc#1137595).
- CVE-2019-11705: Fixed a stack-based buffer overflow in icalrecur_add_bydayrules() (bsc#1137595).
- CVE-2019-11706: Fixed a type confusion in icaltimezone_get_vtimezone_properties() (bsc#1137595).
- CVE-2019-11707: Fixed a type confusion in Array.pop (bsc#1138872).
- CVE-2019-11708: Fixed a sandbox escape using Prompt:Open (bsc#1138872).
Список пакетов
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Workstation Extension 15 SP1
Ссылки
- Link for SUSE-SU-2019:1683-1
- E-Mail link for SUSE-SU-2019:1683-1
- SUSE Security Ratings
- SUSE Bug 1137595
- SUSE Bug 1138872
- SUSE CVE CVE-2019-11703 page
- SUSE CVE CVE-2019-11704 page
- SUSE CVE CVE-2019-11705 page
- SUSE CVE CVE-2019-11706 page
- SUSE CVE CVE-2019-11707 page
- SUSE CVE CVE-2019-11708 page
Описание
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
Затронутые продукты
Ссылки
- CVE-2019-11703
- SUSE Bug 1137595
Описание
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
Затронутые продукты
Ссылки
- CVE-2019-11704
- SUSE Bug 1137595
Описание
A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
Затронутые продукты
Ссылки
- CVE-2019-11705
- SUSE Bug 1137595
Описание
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash. This vulnerability affects Thunderbird < 60.7.1.
Затронутые продукты
Ссылки
- CVE-2019-11706
- SUSE Bug 1137595
Описание
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.
Затронутые продукты
Ссылки
- CVE-2019-11707
- SUSE Bug 1138614
Описание
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.
Затронутые продукты
Ссылки
- CVE-2019-11708
- SUSE Bug 1138872