When a BigInt was right-shifted the backing store was not properly cleared,
allowing uninitialized memory to be read (CVE-2020-16042).
Certain blit values provided by the user were not properly constrained leading
to a heap buffer overflow in WebGL on some video drivers (CVE-2020-26971).
Certain input to the CSS Sanitizer confused it, resulting in incorrect
components being removed. This could have been used as a sanitizer bypass
(CVE-2020-26973).
When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object
could have been incorrectly cast to the wrong type. This resulted in a heap
user-after-free, memory corruption, and a potentially exploitable crash
(CVE-2020-26974).
Using techniques that built on the slipstream research, a malicious webpage
could have exposed both an internal network's hosts as well as services running
on the user's local machine (CVE-2020-26978).
...
- https://bugs.mageia.org/show_bug.cgi?id=27826
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-56/
- https://www.thunderbird.net/en-US/thunderbird/78.6.0/releasenotes/
- https://www.cve.org/CVERecord?id=CVE-2020-16042
- https://www.cve.org/CVERecord?id=CVE-2020-26971
- https://www.cve.org/CVERecord?id=CVE-2020-26973
- https://www.cve.org/CVERecord?id=CVE-2020-26974
- https://www.cve.org/CVERecord?id=CVE-2020-26978
- https://www.cve.org/CVERecord?id=CVE-2020-35111
- https://www.cve.org/CVERecord?id=CVE-2020-35113
- 7/core/thunderbird-78.6.0-1.mga7
- 7/core/thunderbird-l10n-78.6.0-1.mga7
Get the latest Linux and open source security news straight to your inbox.