ALT-BU-2019-3469-1
Branch sisyphus update bulletin.
Package firefox-esr updated to version 60.5.0-alt1 for branch sisyphus in task 220353.
Closed vulnerabilities
BDU:2019-00819
Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с ошибками реализации механизма аутентификации межпроцессного взаимодействия (IPC), позволяющая нарушителю повысить свои привилегии и выйти из изолированной программной среды
BDU:2019-00820
Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, вызванная выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код
BDU:2019-00821
Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код
BDU:2019-00919
Уязвимость веб-браузеров Firefox, Firefox ESR и программы для работы с электронной почтой Thunderbird, связанная с переполнением буфера в памяти, позволяющая нарушителю выполнить произвольный код
BDU:2019-00920
Уязвимость веб-браузеров Firefox, Firefox ESR и программы для работы с электронной почтой Thunderbird, связанная с обращением к освобожденной ячейке памяти, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2018-18500
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
- openSUSE-SU-2019:1758
- openSUSE-SU-2019:1758
- 106781
- 106781
- RHSA-2019:0218
- RHSA-2019:0218
- RHSA-2019:0219
- RHSA-2019:0219
- RHSA-2019:0269
- RHSA-2019:0269
- RHSA-2019:0270
- RHSA-2019:0270
- [debian-lts-announce] 20190130 [SECURITY] [DLA 1648-1] firefox-esr security update
- [debian-lts-announce] 20190130 [SECURITY] [DLA 1648-1] firefox-esr security update
- [debian-lts-announce] 20190216 [SECURITY] [DLA 1678-1] thunderbird security update
- [debian-lts-announce] 20190216 [SECURITY] [DLA 1678-1] thunderbird security update
- GLSA-201903-04
- GLSA-201903-04
- GLSA-201904-07
- GLSA-201904-07
- USN-3874-1
- USN-3874-1
- USN-3897-1
- USN-3897-1
- DSA-4376
- DSA-4376
- DSA-4392
- DSA-4392
- https://www.mozilla.org/security/advisories/mfsa2019-01/
- https://www.mozilla.org/security/advisories/mfsa2019-01/
- https://www.mozilla.org/security/advisories/mfsa2019-02/
- https://www.mozilla.org/security/advisories/mfsa2019-02/
- https://www.mozilla.org/security/advisories/mfsa2019-03/
- https://www.mozilla.org/security/advisories/mfsa2019-03/
Modified: 2024-11-21
CVE-2018-18501
Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
- openSUSE-SU-2019:1758
- openSUSE-SU-2019:1758
- 106781
- 106781
- RHSA-2019:0218
- RHSA-2019:0218
- RHSA-2019:0219
- RHSA-2019:0219
- RHSA-2019:0269
- RHSA-2019:0269
- RHSA-2019:0270
- RHSA-2019:0270
- [debian-lts-announce] 20190130 [SECURITY] [DLA 1648-1] firefox-esr security update
- [debian-lts-announce] 20190130 [SECURITY] [DLA 1648-1] firefox-esr security update
- [debian-lts-announce] 20190216 [SECURITY] [DLA 1678-1] thunderbird security update
- [debian-lts-announce] 20190216 [SECURITY] [DLA 1678-1] thunderbird security update
- GLSA-201903-04
- GLSA-201903-04
- GLSA-201904-07
- GLSA-201904-07
- USN-3874-1
- USN-3874-1
- USN-3897-1
- USN-3897-1
- DSA-4376
- DSA-4376
- DSA-4392
- DSA-4392
- https://www.mozilla.org/security/advisories/mfsa2019-01/
- https://www.mozilla.org/security/advisories/mfsa2019-01/
- https://www.mozilla.org/security/advisories/mfsa2019-02/
- https://www.mozilla.org/security/advisories/mfsa2019-02/
- https://www.mozilla.org/security/advisories/mfsa2019-03/
- https://www.mozilla.org/security/advisories/mfsa2019-03/
Modified: 2024-11-21
CVE-2018-18505
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
- openSUSE-SU-2019:1758
- openSUSE-SU-2019:1758
- 106781
- 106781
- RHSA-2019:0218
- RHSA-2019:0218
- RHSA-2019:0219
- RHSA-2019:0219
- RHSA-2019:0269
- RHSA-2019:0269
- RHSA-2019:0270
- RHSA-2019:0270
- https://bugzilla.mozilla.org/show_bug.cgi?id=1087565
- https://bugzilla.mozilla.org/show_bug.cgi?id=1087565
- [debian-lts-announce] 20190130 [SECURITY] [DLA 1648-1] firefox-esr security update
- [debian-lts-announce] 20190130 [SECURITY] [DLA 1648-1] firefox-esr security update
- [debian-lts-announce] 20190216 [SECURITY] [DLA 1678-1] thunderbird security update
- [debian-lts-announce] 20190216 [SECURITY] [DLA 1678-1] thunderbird security update
- GLSA-201903-04
- GLSA-201903-04
- GLSA-201904-07
- GLSA-201904-07
- USN-3874-1
- USN-3874-1
- USN-3897-1
- USN-3897-1
- DSA-4376
- DSA-4376
- DSA-4392
- DSA-4392
- https://www.mozilla.org/security/advisories/mfsa2019-01/
- https://www.mozilla.org/security/advisories/mfsa2019-01/
- https://www.mozilla.org/security/advisories/mfsa2019-02/
- https://www.mozilla.org/security/advisories/mfsa2019-02/
- https://www.mozilla.org/security/advisories/mfsa2019-03/
- https://www.mozilla.org/security/advisories/mfsa2019-03/
Package thunderbird updated to version 60.5.0-alt1 for branch sisyphus in task 220357.
Closed vulnerabilities
BDU:2019-00819
Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с ошибками реализации механизма аутентификации межпроцессного взаимодействия (IPC), позволяющая нарушителю повысить свои привилегии и выйти из изолированной программной среды
BDU:2019-00820
Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, вызванная выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код
BDU:2019-00821
Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код
BDU:2019-00919
Уязвимость веб-браузеров Firefox, Firefox ESR и программы для работы с электронной почтой Thunderbird, связанная с переполнением буфера в памяти, позволяющая нарушителю выполнить произвольный код
BDU:2019-00920
Уязвимость веб-браузеров Firefox, Firefox ESR и программы для работы с электронной почтой Thunderbird, связанная с обращением к освобожденной ячейке памяти, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2020-00726
Уязвимость почтового клиента Thunderbird, связаная с использованием памяти после освобождения, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2016-5824
libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.
- [oss-security] 20160625 Re: libical 0.47 SEGV on unknown address
- [oss-security] 20160625 Re: libical 0.47 SEGV on unknown address
- [oss-security] 20170120 Re: CVE-2016-9584: heap use-after-free on libical
- [oss-security] 20170120 Re: CVE-2016-9584: heap use-after-free on libical
- 91459
- 91459
- RHSA-2019:0269
- RHSA-2019:0269
- RHSA-2019:0270
- RHSA-2019:0270
- https://bugzilla.mozilla.org/show_bug.cgi?id=1275400
- https://bugzilla.mozilla.org/show_bug.cgi?id=1275400
- https://github.com/libical/libical/issues/235
- https://github.com/libical/libical/issues/235
- https://github.com/libical/libical/issues/251
- https://github.com/libical/libical/issues/251
- https://github.com/libical/libical/issues/286
- https://github.com/libical/libical/issues/286
- GLSA-201904-02
- GLSA-201904-02
- GLSA-201904-07
- GLSA-201904-07
- USN-3897-1
- USN-3897-1
Modified: 2024-11-21
CVE-2018-18500
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
- openSUSE-SU-2019:1758
- openSUSE-SU-2019:1758
- 106781
- 106781
- RHSA-2019:0218
- RHSA-2019:0218
- RHSA-2019:0219
- RHSA-2019:0219
- RHSA-2019:0269
- RHSA-2019:0269
- RHSA-2019:0270
- RHSA-2019:0270
- [debian-lts-announce] 20190130 [SECURITY] [DLA 1648-1] firefox-esr security update
- [debian-lts-announce] 20190130 [SECURITY] [DLA 1648-1] firefox-esr security update
- [debian-lts-announce] 20190216 [SECURITY] [DLA 1678-1] thunderbird security update
- [debian-lts-announce] 20190216 [SECURITY] [DLA 1678-1] thunderbird security update
- GLSA-201903-04
- GLSA-201903-04
- GLSA-201904-07
- GLSA-201904-07
- USN-3874-1
- USN-3874-1
- USN-3897-1
- USN-3897-1
- DSA-4376
- DSA-4376
- DSA-4392
- DSA-4392
- https://www.mozilla.org/security/advisories/mfsa2019-01/
- https://www.mozilla.org/security/advisories/mfsa2019-01/
- https://www.mozilla.org/security/advisories/mfsa2019-02/
- https://www.mozilla.org/security/advisories/mfsa2019-02/
- https://www.mozilla.org/security/advisories/mfsa2019-03/
- https://www.mozilla.org/security/advisories/mfsa2019-03/
Modified: 2024-11-21
CVE-2018-18501
Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
- openSUSE-SU-2019:1758
- openSUSE-SU-2019:1758
- 106781
- 106781
- RHSA-2019:0218
- RHSA-2019:0218
- RHSA-2019:0219
- RHSA-2019:0219
- RHSA-2019:0269
- RHSA-2019:0269
- RHSA-2019:0270
- RHSA-2019:0270
- [debian-lts-announce] 20190130 [SECURITY] [DLA 1648-1] firefox-esr security update
- [debian-lts-announce] 20190130 [SECURITY] [DLA 1648-1] firefox-esr security update
- [debian-lts-announce] 20190216 [SECURITY] [DLA 1678-1] thunderbird security update
- [debian-lts-announce] 20190216 [SECURITY] [DLA 1678-1] thunderbird security update
- GLSA-201903-04
- GLSA-201903-04
- GLSA-201904-07
- GLSA-201904-07
- USN-3874-1
- USN-3874-1
- USN-3897-1
- USN-3897-1
- DSA-4376
- DSA-4376
- DSA-4392
- DSA-4392
- https://www.mozilla.org/security/advisories/mfsa2019-01/
- https://www.mozilla.org/security/advisories/mfsa2019-01/
- https://www.mozilla.org/security/advisories/mfsa2019-02/
- https://www.mozilla.org/security/advisories/mfsa2019-02/
- https://www.mozilla.org/security/advisories/mfsa2019-03/
- https://www.mozilla.org/security/advisories/mfsa2019-03/
Modified: 2024-11-21
CVE-2018-18505
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
- openSUSE-SU-2019:1758
- openSUSE-SU-2019:1758
- 106781
- 106781
- RHSA-2019:0218
- RHSA-2019:0218
- RHSA-2019:0219
- RHSA-2019:0219
- RHSA-2019:0269
- RHSA-2019:0269
- RHSA-2019:0270
- RHSA-2019:0270
- https://bugzilla.mozilla.org/show_bug.cgi?id=1087565
- https://bugzilla.mozilla.org/show_bug.cgi?id=1087565
- [debian-lts-announce] 20190130 [SECURITY] [DLA 1648-1] firefox-esr security update
- [debian-lts-announce] 20190130 [SECURITY] [DLA 1648-1] firefox-esr security update
- [debian-lts-announce] 20190216 [SECURITY] [DLA 1678-1] thunderbird security update
- [debian-lts-announce] 20190216 [SECURITY] [DLA 1678-1] thunderbird security update
- GLSA-201903-04
- GLSA-201903-04
- GLSA-201904-07
- GLSA-201904-07
- USN-3874-1
- USN-3874-1
- USN-3897-1
- USN-3897-1
- DSA-4376
- DSA-4376
- DSA-4392
- DSA-4392
- https://www.mozilla.org/security/advisories/mfsa2019-01/
- https://www.mozilla.org/security/advisories/mfsa2019-01/
- https://www.mozilla.org/security/advisories/mfsa2019-02/
- https://www.mozilla.org/security/advisories/mfsa2019-02/
- https://www.mozilla.org/security/advisories/mfsa2019-03/
- https://www.mozilla.org/security/advisories/mfsa2019-03/
Modified: 2024-11-21
CVE-2018-18513
A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service (DOS) attack because Thunderbird reopens the last seen message on restart, triggering the crash again. This vulnerability affects Thunderbird < 60.5.