Monday, February 1, 2021

ESB-2021.0339 – [Debian] thunderbird: Multiple vulnerabilities

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2021.0339
                        thunderbird security update
                              1 February 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           thunderbird
Publisher:         Debian
Operating System:  Debian GNU/Linux
Impact/Access:     Execute Arbitrary Code/Commands -- Remote with User Interaction
                   Denial of Service               -- Remote with User Interaction
                   Access Confidential Data        -- Remote with User Interaction
                   Reduced Security                -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2021-23964 CVE-2021-23960 CVE-2021-23954
                   CVE-2021-23953 CVE-2020-26976 CVE-2020-16044
                   CVE-2020-15685  

Reference:         ASB-2021.0035
                   ESB-2021.0333
                   ESB-2021.0332
                   ESB-2021.0323
                   ESB-2021.0321

Original Bulletin: 
   http://www.debian.org/security/2021/dsa-4842

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-4842-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
January 31, 2021                      https://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : thunderbird
CVE ID         : CVE-2020-15685 CVE-2020-16044 CVE-2020-26976 CVE-2021-23953 
                 CVE-2021-23954 CVE-2021-23960 CVE-2021-23964

Multiple security issues have been found in Thunderbird, which may lead
to the execution of arbitrary code, denial of service or an information
leak.

For the stable distribution (buster), these problems have been fixed in
version 1:78.7.0-1~deb10u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmAXHIUACgkQEMKTtsN8
TjYQoxAAqM/S2aU96mroe+0UyRB93JSn1c0LThNkzHvCAWqkQsCN1uaGuklI5WLa
wfDx8bxmV1TOcaxTCH1RbGfaupTrIztGP00ti3MIN2hxHdCccfbSL0NI705SRjq/
itCSHgcP6igfGMPbKiqii8KW4BXZjn6tLp2jIvWt5sWnhuMVi3z3Pai5H6b91wCj
tLIOqxgKkLQ8bcJIkLE+jcAJS/UkrcsqsC1ffc678t+qTEtRjgCSCEy3xU/1ZuGp
jyOj+WzneD9ece6Phn5w9Fo415hHkbtLcD3r3ILKkT420hu9joV6a5J46F08U6/D
gXl+DtzvPcjlZJe7lCTqVdr2XJ9EpKto0malgeuooajtvz3SPE+08vvC101yJeId
/nhfJ7YFUhztDTyG8DC5bSTCArt/c+4dw7gtji2bYItjiiRSEqIN5Gh5ZyEyDFV7
WwgZ6+z4+AJkoLffHK501CETs9d6mdfDsaqz6JqgQ6zSwrfjXVmLqu0auiJNjhSX
H0jvoyhXlwVrxkWrePBlCHAw5qVsidku/iXxEO1D+sbgoA6meoSALvhInYWPNI3y
OXr46etKAwPsASV7Qo4vix8SJi0XwycY8bPopsitnje7FNGAenCH2Z6evd2JzEvt
jmMhDwqGFZAvWAXCBeqwvvkrWlvJE50WR/+WDoqdnb9i4FHK20Y=
=jErN
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYBdiHONLKJtyKPYoAQgT/w/6Axtn1HiJeUwiK+AunOg8DkppkE0PP09X
tCMOXcSDxLAaDzHsBSmGNyPw+K4CSIdsWon5n5qVkktSQYbdW2LvWv8Pos+YhZ6v
H1yXlaUpEQyn9WIZ0HGO6cvpcbd870xZ8F26fEVUkvS58B5YGwibYE2Gl5rhM7rh
geZUkFXX69mT43psLmxzPMEP/OCADdsYex79+/vpYzKWj6uDv/USdlr9fik6nhyM
IQHEirbZ1sZeUFRXywgS07iCY9OhIaSfw6q52zducNPB8k9JwMv9GYpaI7i2nHmU
eysmnwfUKQIpE6ZjEmcjtYb7h2FW6UZczf8wTZV3QCiWbit1aTzzh34MSY5dobqv
INwIrVxN1tUIVzorOpduQ+n7UN5JM3DNn9QJgu28rTxOzjzd7CcvqIKzHcwl47RW
wAoK4LbwOg+sGHdJXqRlcctMgyRMj0Blc4/0DoSSoTZ0XXJD+V8UZ+b41ee2fPwa
rSDFlHJ4OiJvjcinT3rJnYd/eqwXvuvXglpRKHud7PFVTjMhf87YKmDB7Q9jlgYd
mhU695eEiXh7uO3BN8CtkXaE60ThELCPUOUdSR40KuuEYqnsCs0aTusSge00Y3EK
Ix7WJ1b8jqYYyDG34OO6BeIZZS9dqg5HdB4PwiLw/U3gxY75pOmZcnMBo7CsEg8e
1Jv1ebePTWo=
=5JdM
-----END PGP SIGNATURE-----

Read More

The post ESB-2021.0339 – [Debian] thunderbird: Multiple vulnerabilities appeared first on Malware Devil.



https://malwaredevil.com/2021/02/01/esb-2021-0339-debian-thunderbird-multiple-vulnerabilities/?utm_source=rss&utm_medium=rss&utm_campaign=esb-2021-0339-debian-thunderbird-multiple-vulnerabilities

No comments:

Post a Comment

Barbary Pirates and Russian Cybercrime

In 1801, the United States had a small Navy. Thomas Jefferson deployed almost half that Navy—three frigates and a schooner—to the Barbary C...