ALT-PU-2018-1491-1
Package thunderbird updated to version 52.7.0-alt0.M80C.1 for branch c8.1 in task 202901.
Closed vulnerabilities
BDU:2018-01494
Уязвимость мультимедийной библиотеки libvorbis, связанная с выходом за границы при чтении буфера памяти, позволяющая нарушителю вызвать отказ в обслуживании или нарушить конфиденциальность и целостность данных
BDU:2021-00069
Уязвимость браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная c выходом операции за границы буфера в памяти, позволяющая нарушителю получить несанкционированный доступ к информации и нарушить ее целостность и доступность
BDU:2021-00375
Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с отсутствием проверки параметров в IPC-сообщениях, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-00392
Уязвимость реализации свойства animatedPathSegList языка разметки SVG браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2023-01886
Уязвимость браузера Mozilla Firefox ESR и почтового клиента Thunderbird, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2018-5125
Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
- 103388
- 103388
- 1040514
- 1040514
- RHSA-2018:0526
- RHSA-2018:0526
- RHSA-2018:0527
- RHSA-2018:0527
- RHSA-2018:0647
- RHSA-2018:0647
- RHSA-2018:0648
- RHSA-2018:0648
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1416529%2C1434580%2C1434384%2C1437450%2C1437507%2C1426988%2C1438425%2C1324042%2C1437087%2C1443865%2C1425520
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1416529%2C1434580%2C1434384%2C1437450%2C1437507%2C1426988%2C1438425%2C1324042%2C1437087%2C1443865%2C1425520
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- GLSA-201810-01
- GLSA-201810-01
- GLSA-201811-13
- GLSA-201811-13
- USN-3545-1
- USN-3545-1
- USN-3596-1
- USN-3596-1
- USN-3688-1
- USN-3688-1
- DSA-4139
- DSA-4139
- DSA-4155
- DSA-4155
- https://www.mozilla.org/security/advisories/mfsa2018-06/
- https://www.mozilla.org/security/advisories/mfsa2018-06/
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
Modified: 2024-11-21
CVE-2018-5127
A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
- 103388
- 103388
- 1040514
- 1040514
- RHSA-2018:0526
- RHSA-2018:0526
- RHSA-2018:0527
- RHSA-2018:0527
- RHSA-2018:0647
- RHSA-2018:0647
- RHSA-2018:0648
- RHSA-2018:0648
- https://bugzilla.mozilla.org/show_bug.cgi?id=1430557
- https://bugzilla.mozilla.org/show_bug.cgi?id=1430557
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- GLSA-201810-01
- GLSA-201810-01
- GLSA-201811-13
- GLSA-201811-13
- USN-3545-1
- USN-3545-1
- USN-3596-1
- USN-3596-1
- DSA-4139
- DSA-4139
- DSA-4155
- DSA-4155
- https://www.mozilla.org/security/advisories/mfsa2018-06/
- https://www.mozilla.org/security/advisories/mfsa2018-06/
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
Modified: 2024-11-21
CVE-2018-5129
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
- 103388
- 103388
- 1040514
- 1040514
- RHSA-2018:0526
- RHSA-2018:0526
- RHSA-2018:0527
- RHSA-2018:0527
- RHSA-2018:0647
- RHSA-2018:0647
- RHSA-2018:0648
- RHSA-2018:0648
- https://bugzilla.mozilla.org/show_bug.cgi?id=1428947
- https://bugzilla.mozilla.org/show_bug.cgi?id=1428947
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- GLSA-201810-01
- GLSA-201810-01
- GLSA-201811-13
- GLSA-201811-13
- USN-3545-1
- USN-3545-1
- USN-3596-1
- USN-3596-1
- DSA-4139
- DSA-4139
- DSA-4155
- DSA-4155
- https://www.mozilla.org/security/advisories/mfsa2018-06/
- https://www.mozilla.org/security/advisories/mfsa2018-06/
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
Modified: 2024-11-21
CVE-2018-5144
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
- 103384
- 103384
- 1040514
- 1040514
- RHSA-2018:0526
- RHSA-2018:0526
- RHSA-2018:0527
- RHSA-2018:0527
- RHSA-2018:0647
- RHSA-2018:0647
- RHSA-2018:0648
- RHSA-2018:0648
- https://bugzilla.mozilla.org/show_bug.cgi?id=1440926
- https://bugzilla.mozilla.org/show_bug.cgi?id=1440926
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- GLSA-201810-01
- GLSA-201810-01
- GLSA-201811-13
- GLSA-201811-13
- USN-3545-1
- USN-3545-1
- DSA-4139
- DSA-4139
- DSA-4155
- DSA-4155
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
Modified: 2024-11-21
CVE-2018-5145
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
- 103384
- 103384
- 1040514
- 1040514
- RHSA-2018:0526
- RHSA-2018:0526
- RHSA-2018:0527
- RHSA-2018:0527
- RHSA-2018:0647
- RHSA-2018:0647
- RHSA-2018:0648
- RHSA-2018:0648
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1261175%2C1348955
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1261175%2C1348955
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180315 [SECURITY] [DLA 1308-1] firefox-esr security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- GLSA-201811-13
- GLSA-201811-13
- USN-3545-1
- USN-3545-1
- DSA-4139
- DSA-4139
- DSA-4155
- DSA-4155
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-07/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
Modified: 2024-11-21
CVE-2018-5146
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
- 103432
- 103432
- 1040544
- 1040544
- RHSA-2018:0549
- RHSA-2018:0549
- RHSA-2018:0647
- RHSA-2018:0647
- RHSA-2018:0648
- RHSA-2018:0648
- RHSA-2018:0649
- RHSA-2018:0649
- RHSA-2018:1058
- RHSA-2018:1058
- https://bugzilla.mozilla.org/show_bug.cgi?id=1446062
- https://bugzilla.mozilla.org/show_bug.cgi?id=1446062
- [debian-lts-announce] 20180326 [SECURITY] [DLA 1319-1] firefox-esr security update
- [debian-lts-announce] 20180326 [SECURITY] [DLA 1319-1] firefox-esr security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1327-1] thunderbird security update
- [debian-lts-announce] 20180430 [SECURITY] [DLA 1368-1] libvorbis security update
- [debian-lts-announce] 20180430 [SECURITY] [DLA 1368-1] libvorbis security update
- GLSA-201811-13
- GLSA-201811-13
- USN-3545-1
- USN-3545-1
- USN-3599-1
- USN-3599-1
- USN-3604-1
- USN-3604-1
- DSA-4140
- DSA-4140
- DSA-4143
- DSA-4143
- DSA-4155
- DSA-4155
- https://www.mozilla.org/security/advisories/mfsa2018-08/
- https://www.mozilla.org/security/advisories/mfsa2018-08/
- https://www.mozilla.org/security/advisories/mfsa2018-09/
- https://www.mozilla.org/security/advisories/mfsa2018-09/