Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Red Hat: RHSA-2017-1201-01 Important: Thunderbird Remote Code Threat

red hat
Calendar Grey May 8, 2017
Scroller Redhat
Canonical reveals a critical Firefox security patch for Ubuntu versions 18.04 and 20.04, resolving various vulnerabilities.
An update for thunderbird is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

All running instances of Thunderbird must be restarted for the update to take effect.

Summary

Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 52.1.0.
Security Fix(es):
* Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2017-5429, CVE-2017-5433, CVE-2017-5435, CVE-2017-5436, CVE-2017-5459, CVE-2017-5466, CVE-2017-5432, CVE-2017-5434, CVE-2017-5438, CVE-2017-5439, CVE-2017-5440, CVE-2017-5441, CVE-2017-5442, CVE-2017-5443, CVE-2017-5444, CVE-2017-5446, CVE-2017-5447, CVE-2017-5454, CVE-2017-5460, CVE-2017-5464, CVE-2017-5465, CVE-2017-5469, CVE-2016-10195, CVE-2016-10196, CVE-2017-5445, CVE-2017-5449, CVE-2017-5451, CVE-2017-5467, CVE-2016-10197)
Red Hat would like to thank the Mozilla project for reporting these issues. Upstream acknowledges Petr Cerny, Nils, Ivan Fratric (Google Project Zero), Takeshi Terada, Heather Miller (Google Skia team), Chun Han Hsiao, Chamal De Silva, Nicolas Grégoire, Holger Fuhrmannek, Atte Kettunen, Haik Aftandilian, and Jordi Chancel as the original reporters.

References

https://access.redhat.com/security/cve/CVE-2016-10195 https://access.redhat.com/security/cve/CVE-2016-10196 https://access.redhat.com/security/cve/CVE-2016-10197 https://access.redhat.com/security/cve/CVE-2017-5429 https://access.redhat.com/security/cve/CVE-2017-5432 https://access.redhat.com/security/cve/CVE-2017-5433 https://access.redhat.com/security/cve/CVE-2017-5434 https://access.redhat.com/security/cve/CVE-2017-5435 https://access.redhat.com/security/cve/CVE-2017-5436 https://access.redhat.com/security/cve/CVE-2017-5438 https://access.redhat.com/security/cve/CVE-2017-5439 https://access.redhat.com/security/cve/CVE-2017-5440 https://access.redhat.com/security/cve/CVE-2017-5441 https://access.redhat.com/security/cve/CVE-2017-5442 https://access.redhat.com/security/cve/CVE-2017-5443 https://access.redhat.com/security/cve/CVE-2017-5444 https://access.redhat.com/security/cve/CVE-2017-5445 https://access.redhat.com/security/cve/CVE-2017-5446 https://access.redhat.com/security/cve/CVE-2017-5447 https://access.redhat.com/security/cve/CVE-2017-5449 https://access.redhat.com/security/cve/CVE-2017-5451 https://access.redhat.com/security/cve/CVE-2017-5454 https://access.redhat.com/security/cve/CVE-2017-5459 https://access.redhat.com/security/cve/CVE-2017-5460 Read the Full Advisory

Package List

Red Hat Enterprise Linux Desktop (v. 6):
Source: thunderbird-52.1.0-1.el6_9.src.rpm
i386: thunderbird-52.1.0-1.el6_9.i686.rpm thunderbird-debuginfo-52.1.0-1.el6_9.i686.rpm
x86_64: thunderbird-52.1.0-1.el6_9.x86_64.rpm thunderbird-debuginfo-52.1.0-1.el6_9.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 6):
Source: thunderbird-52.1.0-1.el6_9.src.rpm
i386: thunderbird-52.1.0-1.el6_9.i686.rpm thunderbird-debuginfo-52.1.0-1.el6_9.i686.rpm
ppc64: thunderbird-52.1.0-1.el6_9.ppc64.rpm thunderbird-debuginfo-52.1.0-1.el6_9.ppc64.rpm
s390x: thunderbird-52.1.0-1.el6_9.s390x.rpm thunderbird-debuginfo-52.1.0-1.el6_9.s390x.rpm
x86_64: thunderbird-52.1.0-1.el6_9.x86_64.rpm thunderbird-debuginfo-52.1.0-1.el6_9.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 6):
Source: thunderbird-52.1.0-1.el6_9.src.rpm
i386: thunderbird-52.1.0-1.el6_9.i686.rpm thunderbird-debuginfo-52.1.0-1.el6_9.i686.rpm
x86_64: thunderbird-52.1.0-1.el6_9.x86_64.rpm thunderbird-debuginfo-52.1.0-1.el6_9.x86_64.rpm
Red Hat Enterprise Linux Client (v. 7):
Source: thunderbird-52.1.0-1.el7_3.src.rpm
x86_64: thunderbird-52.1.0-1.el7_3.x86_64.rpm thunderbird-debuginfo-52.1.0-1.el7_3.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
Source: thunderbird-52.1.0-1.el7_3.src.rpm
aarch64:

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2017:1201-01
Product: Red Hat Enterprise Linux
Issue date: 2017-05-08

Topic

An update for thunderbird is now available for Red Hat Enterprise Linux 6and Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux Client (v. 7) - x86_64

Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64

Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64

Red Hat Enterprise Linux Server Optional (v. 7) - aarch64, ppc64le, x86_64

Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64

Red Hat Enterprise Linux Workstation (v. 7) - x86_64

Bugs Fixed

1418608 - CVE-2016-10195 libevent: Stack-buffer overflow in the name_parse() function

1418611 - CVE-2016-10196 libevent: Stack-buffer overflow in evutil_parse_sockaddr_port()

1418612 - CVE-2016-10197 libevent: Out-of-bounds read in search_make_new()

1443298 - CVE-2017-5442 Mozilla: Use-after-free during style changes (MFSA 2017-11, MFSA 2017-12)

1443299 - CVE-2017-5443 Mozilla: Out-of-bounds write during BinHex decoding (MFSA 2017-11, MFSA 2017-12)

1443301 - CVE-2017-5429 Mozilla: Memory safety bugs fixed in Firefox 53, Firefox ESR 45.9, and Firefox ESR 52.1 (MFSA 2017-11, MFSA 2017-12)

1443303 - CVE-2017-5464 Mozilla: Memory corruption with accessibility and DOM manipulation (MFSA 2017-11, MFSA 2017-12)

1443304 - CVE-2017-5465 Mozilla: Out-of-bounds read in ConvolvePixel (MFSA 2017-11, MFSA 2017-12)

1443305 - CVE-2017-5466 Mozilla: Origin confusion when reloading isolated data:text/html URL (MFSA 2017-12)

1443307 - CVE-2017-5467 Mozilla: Memory corruption when drawing Skia content (MFSA 2017-12)

1443308 - CVE-2017-5460 Mozilla: Use-after-free in frame selection (MFSA 2017-11, MFSA 2017-12)

1443311 - CVE-2017-5449 Mozilla: Crash during bidirectional unicode manipulation with animation (MFSA 2017-11, MFSA 2017-12)

1443312 - CVE-2017-5446 Mozilla: Out-of-bounds read when HTTP/2 DATA frames are sent with incorrect data (MFSA 2017-11, MFSA 2017-12)

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.