Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Mageia: 2020-0034 Moderate: Fix for Thunderbird Security Issues

mageia
Calendar Grey January 11, 2020
Dist Mageia Esm H88
New Thunderbird updates resolve various security vulnerabilities, significantly boosting overall protection following critical risk disclosure.
Updated thunderbird packages fix security vulnerabilities: Bypass of @namespace CSS sanitization during pasting (CVE-2019-17016) Type Confusion in XPCVariant.cpp (CVE-2019-17017)...

Summary

Updated thunderbird packages fix security vulnerabilities:
Bypass of @namespace CSS sanitization during pasting (CVE-2019-17016)
Type Confusion in XPCVariant.cpp (CVE-2019-17017)
CSS sanitization does not escape HTML tags (CVE-2019-17022)
Memory safety bugs fixed in Thunderbird 68.4.1 (CVE-2019-17024)
IonMonkey type confusion with StoreElementHole and FallibleStoreElement (CVE-2019-17026)
Enigmail has been updated to 2.15

References

- https://bugs.mageia.org/show_bug.cgi?id=26047

- https://www.mozilla.org/en-US/security/advisories/mfsa2020-04/

- https://www.thunderbird.net/en-US/thunderbird/68.4.1/releasenotes/

- https://enigmail.net/index.php/en/download/changelog#enig2.1.5

- https://www.cve.org/CVERecord?id=CVE-2019-17016

- https://www.cve.org/CVERecord?id=CVE-2019-17017

- https://www.cve.org/CVERecord?id=CVE-2019-17022

- https://www.cve.org/CVERecord?id=CVE-2019-17024

- https://www.cve.org/CVERecord?id=CVE-2019-17026

Resolution

SRPMS

- 7/core/thunderbird-68.4.1-1.mga7

- 7/core/thunderbird-l10n-68.4.1-1.mga7

Publication date: 11 Jan 2020
URL: https://advisories.mageia.org/MGASA-2020-0034.html
Type: security
CVE: CVE-2019-17016, CVE-2019-17017, CVE-2019-17022, CVE-2019-17024, CVE-2019-17026

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here