This update upgrades Thunderbird to version 60.5.0. * Mozilla: Use-after-free parsing HTML5 stream (CVE-2018-18500) * Mozilla: Memory safety bugs fixed in Firefox 65 and Firefox ESR 60.5 (CVE-2018-18501) * Mozilla: Privilege escalation through IPC channel messages (CVE-2018-18505) * libical: Multiple use-after-free vulnerabilities (CVE-2016-5824) SL7 x86_64 thunderbird-60.5.0-1.el7_6. [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2019:0270-1 Issue Date: 2019-02-04 CVE Numbers: CVE-2018-18500 CVE-2018-18501 CVE-2018-18505 CVE-2016-5824 -- This update upgrades Thunderbird to version 60.5.0. Security Fix(es): * Mozilla: Use-after-free parsing HTML5 stream (CVE-2018-18500) * Mozilla: Memory safety bugs fixed in Firefox 65 and Firefox ESR 60.5 (CVE-2018-18501) * Mozilla: Privilege escalation through IPC channel messages (CVE-2018-18505) * libical: Multiple use-after-free vulnerabilities (CVE-2016-5824) -- SL7 x86_64 thunderbird-60.5.0-1.el7_6.x86_64.rpm thunderbird-debuginfo-60.5.0-1.el7_6.x86_64.rpm - Scientific Linux Development Team . Crucial Thunderbird enhancement for Scientific Linux tackling various vulnerabilities and improving user protection.. Thunderbird Update, Security Fixes, Scientific Linux Advisory. . Severity: Important. LinuxSecurity.com Team
This update upgrades Thunderbird to version 60.5.0. * Mozilla: Use-after-free parsing HTML5 stream (CVE-2018-18500) * Mozilla: Memory safety bugs fixed in Firefox 65 and Firefox ESR 60.5 (CVE-2018-18501) * Mozilla: Privilege escalation through IPC channel messages (CVE-2018-18505) * libical: Multiple use-after-free vulnerabilities (CVE-2016-5824) SL6 x86_64 thunderbird-60.5.0-1.el6_10 [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2019:0269-1 Issue Date: 2019-02-04 CVE Numbers: CVE-2018-18500 CVE-2018-18501 CVE-2018-18505 CVE-2016-5824 -- This update upgrades Thunderbird to version 60.5.0. Security Fix(es): * Mozilla: Use-after-free parsing HTML5 stream (CVE-2018-18500) * Mozilla: Memory safety bugs fixed in Firefox 65 and Firefox ESR 60.5 (CVE-2018-18501) * Mozilla: Privilege escalation through IPC channel messages (CVE-2018-18505) * libical: Multiple use-after-free vulnerabilities (CVE-2016-5824) -- SL6 x86_64 thunderbird-60.5.0-1.el6_10.x86_64.rpm thunderbird-debuginfo-60.5.0-1.el6_10.x86_64.rpm i386 thunderbird-60.5.0-1.el6_10.i686.rpm thunderbird-debuginfo-60.5.0-1.el6_10.i686.rpm - Scientific Linux Development Team . Enhance Thunderbird to version 60.5.0 addressing HTML5 streaming and memory security vulnerabilities for SL6 platforms.. thunderbird update, use-after-free, security fix, memory safety, privilege escalation. . Severity: Important. LinuxSecurity.com Team
It was discovered that there was a use-after-free vulnerability in the libical iCalendar library. Remote attackers could cause a denial of service and possibly read heap memory via a specially crafted .ICS file. . Hash: SHA256 Package : libical Version : 0.48-2+deb7u1 CVE ID : CVE-2016-5824 CVE-2016-9584 Debian Bug : #860451, #852034 It was discovered that there was a use-after-free vulnerability in the libical iCalendar library. Remote attackers could cause a denial of service and possibly read heap memory via a specially crafted .ICS file. For Debian 7 "Wheezy", this issue has been fixed in libical version 0.48-2+deb7u1. We recommend that you upgrade your libical packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Get the latest Linux and open source security news straight to your inbox.