This update upgrades Thunderbird to version 52.9.1. * Mozilla: Memory safety bugs fixed in Firefox 61, Firefox ESR 60.1, and Firefox ESR 52.9 (CVE-2018-5188) * Mozilla: Buffer overflow using computed size of canvas element (CVE-2018-12359) * Mozilla: Use-after-free using focus() (CVE-2018-12360) * Mozilla: Integer overflow in SSSE3 scaler (CVE-2018-12362) * Mozilla: Use-after-free when appe [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2018:2251-1 Issue Date: 2018-07-25 CVE Numbers: CVE-2018-12359 CVE-2018-12360 CVE-2018-12362 CVE-2018-12363 CVE-2018-12364 CVE-2018-12365 CVE-2018-12366 CVE-2018-5188 CVE-2018-12373 CVE-2018-12372 CVE-2018-12374 -- This update upgrades Thunderbird to version 52.9.1. Security Fix(es): * Mozilla: Memory safety bugs fixed in Firefox 61, Firefox ESR 60.1, and Firefox ESR 52.9 (CVE-2018-5188) * Mozilla: Buffer overflow using computed size of canvas element (CVE-2018-12359) * Mozilla: Use-after-free using focus() (CVE-2018-12360) * Mozilla: Integer overflow in SSSE3 scaler (CVE-2018-12362) * Mozilla: Use-after-free when appending DOM nodes (CVE-2018-12363) * Mozilla: CSRF attacks through 307 redirects and NPAPI plugins (CVE-2018-12364) * thunderbird: S/MIME and PGP decryption oracles can be built with HTML emails (CVE-2018-12372) * thunderbird: S/MIME plaintext can be leaked through HTML reply/forward (CVE-2018-12373) * Mozilla: Compromised IPC child process can list local filenames (CVE-2018-12365) * Mozilla: Invalid data handling during QCMS transformations (CVE-2018-12366) * thunderbird: Using form to exfiltrate encrypted mail part by pressing enter in form field (CVE-2018-12374) -- SL6 x86_64 thunderbird-52.9.1-1.el6.x86_64.rpm thunderbird-debuginfo-52.9.1-1.el6.x86_64.rpm i386 thunderbird-52.9.1-1.el6.i686.rpm thunderbird-debuginfo-52.9.1-1.el6.i686.rpm - Scientific Linux Development Team . Crucial enhancements to Thunderbird's security protocols, prioritizing the resolution of significant vulnerabilities with timely updates and patches.. thunderbird security, buffer overflow, memory safety, Mozilla issues, SL6 updates. . Severity: Important. LinuxSecurity.com Team
A new exploitation technique called key reinstallation attacks (KRACK) affecting WPA2 has been discovered. A remote attacker within Wi-Fi range could exploit these attacks to decrypt Wi-Fi traffic or possibly inject forged Wi-Fi packets by manipulating cryptographic handshakes used by the WPA2 protocol. (CVE-2017-13077, CVE-2017-13078, CVE-2017-13080, CVE-2017-13082, CVE-2017-13086, CVE-2017-1 [More...]. Synopsis: Important: wpa_supplicant security update Advisory ID: SLSA-2017:2907-1 Issue Date: 2017-10-18 CVE Numbers: CVE-2017-13077 CVE-2017-13078 CVE-2017-13080 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 -- Security Fix(es): * A new exploitation technique called key reinstallation attacks (KRACK) affecting WPA2 has been discovered. A remote attacker within Wi-Fi range could exploit these attacks to decrypt Wi-Fi traffic or possibly inject forged Wi-Fi packets by manipulating cryptographic handshakes used by the WPA2 protocol. (CVE-2017-13077, CVE-2017-13078, CVE-2017-13080, CVE-2017-13082, CVE-2017-13086, CVE-2017-13087, CVE-2017-13088) -- SL7 x86_64 wpa_supplicant-2.6-5.el7_4.1.x86_64.rpm wpa_supplicant-debuginfo-2.6-5.el7_4.1.x86_64.rpm - Scientific Linux Development Team . Key reinstallation vulnerabilities impact wpa_supplicant in the SL7 framework, enabling potential remote exploitation after the security patch SLSA-2017-2907-1. wpa_supplicant Security Update, KRACK Attack, SL7 Network Security. . Severity: Critical. LinuxSecurity.com Team
GnuPG could expose sensitive information when performing decryption.. =========================================================================Ubuntu Security Notice USN-2339-1 September 03, 2014 gnupg vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: GnuPG could expose sensitive information when performing decryption. Software Description: - gnupg: GNU privacy guard - a free PGP replacement Details: Daniel Genkin, Adi Shamir, and Eran Tromer discovered that GnuPG was susceptible to an adaptive chosen ciphertext attack via physical side channels. A local attacker could use this attack to possibly recover private keys. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: gnupg 1.4.11-3ubuntu2.7 Ubuntu 10.04 LTS: gnupg 1.4.10-2ubuntu1.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2339-1 CVE-2014-5270 Package Information: https://launchpad.net/ubuntu/+source/gnupg/1.4.11-3ubuntu2.7 https://launchpad.net/ubuntu/+source/gnupg/1.4.10-2ubuntu1.7 . Critical data could be compromised owing to GnuPG weaknesses in certain Ubuntu releases. Patch promptly for protection!. GnuPG Vulnerability, Ubuntu Security Notice, Information Exposure. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.