KLA11591
Multiple vulnerabilities in Mozilla Thunderbird
Updated: 05/22/2020
Detect date
?
09/22/2019
Severity
?
Critical
Description

Multiple vulnerabilities were found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. Vulnerability related to document.domain can be exploited to execute arbitrary code;
  2. Stack buffer overflow vulnerability can be exploited to cause denial of service;
  3. Vulnerability related to 360 Total Security can be exploited to execute arbitrary code;
  4. Vulnerability related to HTML parsing can be exploited remotely to bypass security restrictions;
  5. Vulnerability can be exploited to bypass security restrictions;
  6. Buffer overflow vulnerability in expat can be exploited to arbitrary code execution;
  7. Memory safety vulnerability can be exploited to execute arbitrary code;
  8. Use-after-free vulnerability can be exploited to cause denial of service.
Affected products

Mozilla Thunderbird earlier than 68.2

Solution

Update to the latest version
Download Mozilla Thunderbird

Original advisories

Advisory 2019-35

Impacts
?
ACE 
[?]

DoS 
[?]

SB 
[?]
Related products
Mozilla Thunderbird
CVE-IDS
?
CVE-2019-159030.0Unknown
CVE-2019-117580.0Unknown
CVE-2019-117610.0Unknown
CVE-2019-117570.0Unknown
CVE-2019-117600.0Unknown
CVE-2019-117590.0Unknown
CVE-2019-117620.0Unknown
CVE-2019-117640.0Unknown
CVE-2019-117630.0Unknown