安全公告详情

NS-SA-2019-0160

2019-08-01 19:03:25

简介

critical: python/thunderbird security update

严重级别

critical

主题

An update for python/thunderbird is now available for NewStart CGSL MAIN 5.04/CGSL CORE 5.04.
NewStart Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

python: The Tkinter (Tk interface) program is an graphical user interface for the Python scripting language. You should install the tkinter package if you'd like to use a graphical user interface for Python programming.
thunderbird: Mozilla Thunderbird is a standalone mail and newsgroup client.


Security Fix(es):
python: A security regression of CVE-2019-9636 was discovered in python, since commit d537ab0ff9767ef024f26246899728f0116b1ec3, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.(CVE-2019-10160)
python: bugfix
thunderbird: A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.(CVE-2019-11703)
thunderbird: A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.(CVE-2019-11705)
thunderbird: A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash. This vulnerability affects Thunderbird < 60.7.1.(CVE-2019-11706)
thunderbird: Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.(CVE-2019-11708)
thunderbird: A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.(CVE-2019-11707)
thunderbird: A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.(CVE-2019-11704)
thunderbird: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 5.04.F16.

影响组件

  • python
  • thunderbird

影响产品

  • CGSL MAIN 5.04
  • CGSL CORE 5.04

更新包

{"fix":[{"product":"CGSL MAIN 5.04","pkgs":[{"binary":["tkinter-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.x86_64.rpm","python-test-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.x86_64.rpm","python-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.x86_64.rpm","python-tools-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.x86_64.rpm","python-libs-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.x86_64.rpm","python-debug-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.x86_64.rpm","python-debuginfo-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.x86_64.rpm","python-devel-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.x86_64.rpm"],"source":"python-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.src.rpm"},{"binary":["thunderbird-60.7.2-2.el7.centos.x86_64.rpm","thunderbird-debuginfo-60.7.2-2.el7.centos.x86_64.rpm"],"source":"thunderbird-60.7.2-2.el7.centos.src.rpm"}]},{"product":"CGSL CORE 5.04","pkgs":[{"binary":["python-libs-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.lite.x86_64.rpm","python-debug-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.lite.x86_64.rpm","python-debuginfo-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.lite.x86_64.rpm","python-devel-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.lite.x86_64.rpm","python-test-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.lite.x86_64.rpm","python-tools-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.lite.x86_64.rpm","python-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.lite.x86_64.rpm","tkinter-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.lite.x86_64.rpm"],"source":"python-2.7.5-80.el7_6.cgslv5.0.1.gf55b118.lite.src.rpm"},{"binary":["thunderbird-60.7.2-2.el7.centos.x86_64.rpm","thunderbird-debuginfo-60.7.2-2.el7.centos.x86_64.rpm"],"source":"thunderbird-60.7.2-2.el7.centos.src.rpm"}]}]}

CVE

参考