Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia: 2019-0275 Moderate: Thunderbird Covert Content Attack

mageia
Calendar Grey September 15, 2019
Dist Mageia Esm H88
Uncover the advancements in Thunderbird versions that tackle critical security vulnerabilities in Mageia, boosting defenses against hidden threats.
Updated thunderbird packages fix security vulnerabilities: Covert Content Attack on S/MIME encryption using a crafted multipart/ alternative message (CVE-2019-11739)

Summary

Updated thunderbird packages fix security vulnerabilities:
Covert Content Attack on S/MIME encryption using a crafted multipart/ alternative message (CVE-2019-11739).
Memory safety bugs fixed in Firefox 69, Firefox ESR 68.1, Firefox ESR 60.9, Thunderbird 68.1, and Thunderbird 60.9 (CVE-2019-11740)
Same-origin policy violation with SVG filters and canvas to steal cross-origin images (CVE-2019-11742)
Cross-origin access to unload event attributes (CVE-2019-11743)
XSS by breaking out of title and textarea elements using innerHTML (CVE-2019-11744)
Use-after-free while manipulating video (CVE-2019-11746)
Use-after-free while extracting a key value in IndexedDB (CVE-2019-11752)

References

- https://bugs.mageia.org/show_bug.cgi?id=25415

- https://www.thunderbird.net/en-US/thunderbird/60.9.0/releasenotes/

- https://www.cve.org/CVERecord?id=CVE-2019-11739

- https://www.cve.org/CVERecord?id=CVE-2019-11740

- https://www.cve.org/CVERecord?id=CVE-2019-11742

- https://www.cve.org/CVERecord?id=CVE-2019-11743

- https://www.cve.org/CVERecord?id=CVE-2019-11744

- https://www.cve.org/CVERecord?id=CVE-2019-11752

Resolution

SRPMS

- 6/core/thunderbird-60.9.0-1.mga6

- 6/core/thunderbird-l10n-60.9.0-1.mga6

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 15 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0275.html
Type: security
CVE: CVE-2019-11739, CVE-2019-11740, CVE-2019-11742, CVE-2019-11743, CVE-2019-11744, CVE-2019-11752

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here