Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2019:1683-1

Опубликовано: 22 июн. 2019
Источник: suse-cvrf

Описание

Security update for MozillaThunderbird

This update for MozillaThunderbird fixes the following issues:

Security issues fixed:

  • CVE-2019-11703: Fixed a heap-based buffer overflow in icalmemorystrdupanddequote() (bsc#1137595).
  • CVE-2019-11704: Fixed a heap-based buffer overflow in parser_get_next_char() (bsc#1137595).
  • CVE-2019-11705: Fixed a stack-based buffer overflow in icalrecur_add_bydayrules() (bsc#1137595).
  • CVE-2019-11706: Fixed a type confusion in icaltimezone_get_vtimezone_properties() (bsc#1137595).
  • CVE-2019-11707: Fixed a type confusion in Array.pop (bsc#1138872).
  • CVE-2019-11708: Fixed a sandbox escape using Prompt:Open (bsc#1138872).

Список пакетов

SUSE Linux Enterprise Workstation Extension 15
MozillaThunderbird-60.7.2-3.43.1
MozillaThunderbird-translations-common-60.7.2-3.43.1
MozillaThunderbird-translations-other-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15 SP1
MozillaThunderbird-60.7.2-3.43.1
MozillaThunderbird-translations-common-60.7.2-3.43.1
MozillaThunderbird-translations-other-60.7.2-3.43.1

Описание

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.


Затронутые продукты
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-common-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-other-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15:MozillaThunderbird-60.7.2-3.43.1

Ссылки

Описание

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.


Затронутые продукты
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-common-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-other-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15:MozillaThunderbird-60.7.2-3.43.1

Ссылки

Описание

A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.


Затронутые продукты
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-common-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-other-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15:MozillaThunderbird-60.7.2-3.43.1

Ссылки

Описание

A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash. This vulnerability affects Thunderbird < 60.7.1.


Затронутые продукты
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-common-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-other-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15:MozillaThunderbird-60.7.2-3.43.1

Ссылки

Описание

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.


Затронутые продукты
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-common-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-other-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15:MozillaThunderbird-60.7.2-3.43.1

Ссылки

Описание

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.


Затронутые продукты
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-common-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-other-60.7.2-3.43.1
SUSE Linux Enterprise Workstation Extension 15:MozillaThunderbird-60.7.2-3.43.1

Ссылки