KLA11524
Multiple vulnerabilities in Mozilla Thunderbird
Обновлено: 19/07/2019
Дата обнаружения
09/07/2019
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to bypass security restrictions, spoof user interface, cause denial of service, perform cross-site scripting attack, obtain sensitive information, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. Unspecified vulnerability can be exploited Fetch API to bypass security restrictions;
  2. Unspecified vulnerability in Thunderbird can be exploited via cross-origin protection to bypass security restrictions;
  3. Unspecified vulnerability in Thunderbird can be exploited to spoof user interface;
  4. Unspecified vulnerability in Thunderbird can be exploited via p256-ECDH public keys forming to cause denial of service;
  5. Unspecified vulnerability in Thunderbird can be exploited via parsing page content to perform cross-site scripting;
  6. A use-after-free vulnerability in Thunderbird can be exploited to cause denial of service;
  7. Out-of-bounds read vulnerability in Thunderbird can be exploited via importing a curve25519 private key to obtain sensitive information;
  8. Unspecified vulnerability in Thunderbird can be exploited via NPAPI plugins to perform cross-site scripting;
  9. Unspecified vulnerability in Thunderbird can be exploited via sandbox to bypass security restrictions;
  10. Multiple memory corruption vulnerabilities can be exploited to execute arbitrary code.
Пораженные продукты

Mozilla Thunderbird earlier than 60.8

Решение

Update to the latest version
Download Mozilla Thunderbird

Первичный источник обнаружения
mfsa2019-23
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

XSS/CSS 
[?]

SUI 
[?]
Связанные продукты
Mozilla Thunderbird
CVE-IDS
CVE-2019-98110.0Unknown
CVE-2019-117110.0Unknown
CVE-2019-117120.0Unknown
CVE-2019-117130.0Unknown
CVE-2019-117290.0Unknown
CVE-2019-117150.0Unknown
CVE-2019-117170.0Unknown
CVE-2019-117190.0Unknown
CVE-2019-117300.0Unknown
CVE-2019-117090.0Unknown