ALT-BU-2019-3739-3
Branch sisyphus update bulletin.
Closed bugs
Собрать с python3
Closed bugs
Не работает, как другие webapps
Package thunderbird updated to version 60.7.1-alt1 for branch sisyphus in task 232284.
Closed vulnerabilities
Modified: 2023-11-21
BDU:2019-03564
Уязвимость функции parser_get_next_char календаря iCal программного обеспечения для работы с электронной почтой Thunderbird, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю оказать воздействие на целостность данных, получить несанкционированный доступ к защищаемой информации, а также вызвать отказ в обслуживании
Modified: 2023-11-21
BDU:2019-03565
Уязвимость функции icalmemory_strdup_and_dequote календаря iCal программного обеспечения для работы с электронной почтой Thunderbird, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю оказать воздействие на целостность данных, получить несанкционированный доступ к защищаемой информации, а также вызвать отказ в обслуживании
Modified: 2023-11-21
BDU:2019-03611
Уязвимость библиотеки libical почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2023-11-21
BDU:2019-03612
Уязвимость библиотеки libical почтового клиента Thunderbird, связанная с отсутствием проверки типа передаваемого объекта (“type confusion”), позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11703
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1553820
- https://security.gentoo.org/glsa/201908-20
- https://www.mozilla.org/security/advisories/mfsa2019-17/
- https://bugzilla.mozilla.org/show_bug.cgi?id=1553820
- https://security.gentoo.org/glsa/201908-20
- https://www.mozilla.org/security/advisories/mfsa2019-17/
Modified: 2024-11-21
CVE-2019-11704
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1553814
- https://security.gentoo.org/glsa/201908-20
- https://www.mozilla.org/security/advisories/mfsa2019-17/
- https://bugzilla.mozilla.org/show_bug.cgi?id=1553814
- https://security.gentoo.org/glsa/201908-20
- https://www.mozilla.org/security/advisories/mfsa2019-17/
Modified: 2024-11-21
CVE-2019-11705
A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1553808
- https://security.gentoo.org/glsa/201908-20
- https://www.mozilla.org/security/advisories/mfsa2019-17/
- https://bugzilla.mozilla.org/show_bug.cgi?id=1553808
- https://security.gentoo.org/glsa/201908-20
- https://www.mozilla.org/security/advisories/mfsa2019-17/
Modified: 2024-11-21
CVE-2019-11706
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash. This vulnerability affects Thunderbird < 60.7.1.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1555646
- https://security.gentoo.org/glsa/201908-20
- https://www.mozilla.org/security/advisories/mfsa2019-17/
- https://bugzilla.mozilla.org/show_bug.cgi?id=1555646
- https://security.gentoo.org/glsa/201908-20
- https://www.mozilla.org/security/advisories/mfsa2019-17/
Closed bugs
thunderbird-enigmail: отсутствует зависимость на pinentry
thunderbird-enigmail 60.6.1 перестал отправлять письма
Package kernel-image-un-def updated to version 5.0.21-alt2 for branch sisyphus in task 232426.
Closed vulnerabilities
Modified: 2024-05-16
BDU:2020-02044
Уязвимость функции brcmf_wowl_nd_results драйвер Broadcom brcmfmac WiFi ядра операционной системы Linux, позволяющая нарушителю получить несанкционированный доступ к информации и нарушить ее целостность и доступность
Modified: 2024-11-21
CVE-2019-9500
The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This vulnerability can be exploited with compromised chipsets to compromise the host, or when used in combination with CVE-2019-9503, can be used remotely. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.
- https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html
- https://git.kernel.org/linus/1b5e2423164b3670e8bc9174e4762d297990deff
- https://kb.cert.org/vuls/id/166939/
- https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html
- https://git.kernel.org/linus/1b5e2423164b3670e8bc9174e4762d297990deff
- https://kb.cert.org/vuls/id/166939/
Closed vulnerabilities
Modified: 2025-05-23
CVE-2017-7957
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("
- http://www.debian.org/security/2017/dsa-3841
- http://www.securityfocus.com/bid/100687
- http://www.securitytracker.com/id/1039499
- http://x-stream.github.io/CVE-2017-7957.html
- https://access.redhat.com/errata/RHSA-2017:1832
- https://access.redhat.com/errata/RHSA-2017:2888
- https://access.redhat.com/errata/RHSA-2017:2889
- https://exchange.xforce.ibmcloud.com/vulnerabilities/125800
- https://www-prd-trops.events.ibm.com/node/715749
- http://www.debian.org/security/2017/dsa-3841
- http://www.securityfocus.com/bid/100687
- http://www.securitytracker.com/id/1039499
- http://x-stream.github.io/CVE-2017-7957.html
- https://access.redhat.com/errata/RHSA-2017:1832
- https://access.redhat.com/errata/RHSA-2017:2888
- https://access.redhat.com/errata/RHSA-2017:2889
- https://exchange.xforce.ibmcloud.com/vulnerabilities/125800
- https://www-prd-trops.events.ibm.com/node/715749
Modified: 2025-05-23
GHSA-7hwc-46rm-65jh
Denial of service in XStream
- https://nvd.nist.gov/vuln/detail/CVE-2017-7957
- https://github.com/x-stream/xstream/commit/6e546ec366419158b1e393211be6d78ab9604ab
- https://github.com/x-stream/xstream/commit/8542d02d9ac5d384c85f4b33d6c1888c53bd55d
- https://github.com/x-stream/xstream/commit/b3570be2f39234e61f99f9a20640756ea71b1b4
- https://access.redhat.com/errata/RHSA-2017:1832
- https://access.redhat.com/errata/RHSA-2017:2888
- https://access.redhat.com/errata/RHSA-2017:2889
- https://exchange.xforce.ibmcloud.com/vulnerabilities/125800
- https://github.com/x-stream/xstream
- https://www-prd-trops.events.ibm.com/node/715749
- http://www.debian.org/security/2017/dsa-3841
- http://www.securityfocus.com/bid/100687
- http://www.securitytracker.com/id/1039499
- http://x-stream.github.io/CVE-2017-7957.html
