Mozilla: Type confusion in Array.pop (CVE-2019-11707) * thunderbird: Stack buffer overflow in icalrecur_add_bydayrules in icalrecur.c (CVE-2019-11705) * Mozilla: Sandbox escape using Prompt:Open (CVE-2019-11708) * thunderbird: Heap buffer over read in icalparser.c parser_get_next_char (CVE-2019-11703) * thunderbird: Heap buffer overflow in icalmemory_strdup_and_dequote function in icalvalu [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2019:1626-1 Issue Date: 2019-06-27 CVE Numbers: None -- Security Fix(es): * Mozilla: Type confusion in Array.pop (CVE-2019-11707) * thunderbird: Stack buffer overflow in icalrecur_add_bydayrules in icalrecur.c (CVE-2019-11705) * Mozilla: Sandbox escape using Prompt:Open (CVE-2019-11708) * thunderbird: Heap buffer over read in icalparser.c parser_get_next_char (CVE-2019-11703) * thunderbird: Heap buffer overflow in icalmemory_strdup_and_dequote function in icalvalue.c (CVE-2019-11704) * thunderbird: Type confusion in icaltimezone_get_vtimezone_properties function in icalproperty.c (CVE-2019-11706) -- SL7 x86_64 thunderbird-60.7.2-2.el7_6.x86_64.rpm thunderbird-debuginfo-60.7.2-2.el7_6.x86_64.rpm - Scientific Linux Development Team . The recent Thunderbird security patch SLSA-2019:1626-1 tackles severe vulnerabilities, specifically targeting buffer overflow and type mismatch problems.. thunderbird update, buffer overflow fix, security advisory, SL7 x86_64. . Severity: Important. LinuxSecurity.com Team
This release fixes a crash when parsing an empty code string of a codewscope type.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-7edc2ea787 2017-09-26 19:35:44.725386 --------------------------------------------------------------------------------Name : libbson Product : Fedora 25 Version : 1.3.5 Release : 4.fc25 URL : https://github.com/mongodb/libbson Summary : Building, parsing, and iterating BSON documents Description : This is a library providing useful routines related to building, parsing, and iterating BSON documents . --------------------------------------------------------------------------------Update Information: This release fixes a crash when parsing an empty code string of a codewscope type. --------------------------------------------------------------------------------References: [ 1 ] Bug #1494401 - CVE-2017-14227 libbson: Heap based buffer over read in the bson_utf8_validate function https://bugzilla.redhat.com/show_bug.cgi?id=1494401 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libbson' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.