Arch Linux Security Advisory ASA-202001-4 ========================================= Severity: Critical Date : 2020-01-14 CVE-ID : CVE-2019-17016 CVE-2019-17017 CVE-2019-17022 CVE-2019-17024 CVE-2019-17026 Package : thunderbird Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1086 Summary ======= The package thunderbird before version 68.4.1-1 is vulnerable to multiple issues including arbitrary code execution and insufficient validation. Resolution ========== Upgrade to 68.4.1-1. # pacman -Syu "thunderbird>=68.4.1-1" The problems have been fixed upstream in version 68.4.1. Workaround ========== None. Description =========== - CVE-2019-17016 (insufficient validation) A security issue has been found in Firefox before 72.0, and Thunderbird before 68.4.1. When pasting a