安全公告详情

NS-SA-2019-0088

2019-07-17 14:59:22

简介

critical: thunderbird security update

严重级别

critical

主题

An update for thunderbird is now available for NewStart CGSL MAIN 5.05/CGSL CORE 5.05.
NewStart Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

thunderbird: Mozilla Thunderbird is a standalone mail and newsgroup client.


Security Fix(es):
thunderbird: png_image_free in png.c in libpng 1.6.36 has a use-after-free because png_image_free_function is called under png_safe_execute.(CVE-2019-7317)
thunderbird: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.(CVE-2019-11698)
thunderbird: Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.(CVE-2019-5798)
thunderbird: oss-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.(CVE-2018-18511)
thunderbird: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.(CVE-2019-11691)
thunderbird: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.(CVE-2019-11692)
thunderbird: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.(CVE-2019-11693)
thunderbird: oss-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.(CVE-2019-9797)
thunderbird: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.(CVE-2019-9800)
thunderbird: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.(CVE-2019-9817)
thunderbird: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.(CVE-2019-9819)
thunderbird: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.(CVE-2019-9820)
thunderbird: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 5.05.F3.

影响组件

  • thunderbird

影响产品

  • CGSL MAIN 5.05
  • CGSL CORE 5.05

更新包

{"fix":[{"product":"CGSL MAIN 5.05","pkgs":[{"binary":["thunderbird-60.7.0-1.el7.centos.x86_64.rpm","thunderbird-debuginfo-60.7.0-1.el7.centos.x86_64.rpm"],"source":"thunderbird-60.7.0-1.el7.centos.src.rpm"}]},{"product":"CGSL CORE 5.05","pkgs":[{"binary":["thunderbird-60.7.0-1.el7.centos.x86_64.rpm","thunderbird-debuginfo-60.7.0-1.el7.centos.x86_64.rpm"],"source":"thunderbird-60.7.0-1.el7.centos.src.rpm"}]}]}

CVE

参考