KLA11561
Multiple vulnerabilities in Mozilla Thunderbird
Updated: 09/25/2019
Detect date
?
09/06/2019
Severity
?
Critical
Description

Multiple vulnerabilities were found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, perform cross-site scripting attack.

Below is a complete list of vulnerabilities:

  1. Unspecified vulnerability can be exploited via side-channel attack to bypass security restrictions;
  2. Use-after-free vulnerability can be exploited via deleting an IndexedDB key to cause denial of service;
  3. Multiple memory corruption vulnerabilities can be exploited to execute arbitrary code.
  4. Unspecified vulnerability can be exploited via HTML tags parsing to perform cross-site scripting attack;
  5. Unspecified vulnerability can be exploited via crafted multipart/alternative message to bypass security restrictions;
  6. Unspecified vulnerability can be exploited via same-origin policy violation to bypass security restrictions;
  7. Use-after-free vulnerability can be exploited via manipulating video to cause denial of service;
Affected products

Mozilla Thunderbird earlier than 60.9

Solution

Update to the latest version
Download Mozilla Thunderbird

Original advisories

mfsa2019-29

Impacts
?
DoS 
[?]

SB 
[?]

XSS/CSS 
[?]
Related products
Mozilla Thunderbird
CVE-IDS
?
CVE-2019-117520.0Unknown
CVE-2019-117460.0Unknown
CVE-2019-117420.0Unknown
CVE-2019-117400.0Unknown
CVE-2019-117440.0Unknown
CVE-2019-117430.0Unknown
CVE-2019-117390.0Unknown