Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Mageia 6: MGASA-2019-0193 Critical: Thunderbird Buffer Overflow Issues

mageia
Calendar Grey June 20, 2019
Dist Mageia Esm H88
Newly released Firefox updates for Mageia address numerous vulnerabilities revealed on June 21, 2019, promoting enhanced security.
The updated thunderbird packages fix some bugs and security vulnerabilities: Heap buffer overflow in icalparser.c

Summary

The updated thunderbird packages fix some bugs and security vulnerabilities:
Heap buffer overflow in icalparser.c. (CVE-2019-11703)
Heap buffer overflow in icalvalue.c. (CVE-2019-11704)
Stack buffer overflow in icalrecur.c. (CVE-2019-11705)
Type confusion in icalproperty.c. (CVE-2019-11706)

References

- https://bugs.mageia.org/show_bug.cgi?id=24953

- https://www.thunderbird.net/en-US/thunderbird/60.7.1/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2019-17/

- https://www.openwall.com/lists/oss-security/2019/06/13/1

- https://www.openwall.com/lists/oss-security/2019/06/13/2

- https://www.openwall.com/lists/oss-security/2019/06/13/3

- https://www.openwall.com/lists/oss-security/2019/06/13/4

- https://www.cve.org/CVERecord?id=CVE-2019-11703

- https://www.cve.org/CVERecord?id=CVE-2019-11704

- https://www.cve.org/CVERecord?id=CVE-2019-11705

- https://www.cve.org/CVERecord?id=CVE-2019-11706

Resolution

SRPMS

- 6/core/thunderbird-60.7.1-1.mga6

- 6/core/thunderbird-l10n-60.7.1-1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 21 Jun 2019
URL: https://advisories.mageia.org/MGASA-2019-0193.html
Type: security
CVE: CVE-2019-11703, CVE-2019-11704, CVE-2019-11705, CVE-2019-11706

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here