AVG-707

Package thunderbird
Status Fixed
Severity Critical
Type multiple issues
Affected 52.7.0-2
Fixed 52.8.0-1
Current 60.7.1-1 [extra]
Ticket None
Created Mon May 21 14:04:15 2018
Issue Severity Remote Type Description
CVE-2018-5185 Low Yes Information disclosure
A security issue has been found in Thunderbird before 52.8, where plaintext of decrypted emails can leak through by user submitting an embedded form.
CVE-2018-5184 High Yes Information disclosure
A security issue has been found in Thunderbird before 52.8, where using remote content in S/MIME encrypted messages can lead to the disclosure of plaintext...
CVE-2018-5183 Critical Yes Arbitrary code execution
Several memory corruption issues including invalid buffer reads and writes during graphic operations have been found in the Skia library.
CVE-2018-5178 Medium Yes Information disclosure
A buffer overflow was found in Thunderbird before 52.8, during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data....
CVE-2018-5170 Medium Yes Content spoofing
It is possible in Thunderbird before 52.8 to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening...
CVE-2018-5168 Medium Yes Access restriction bypass
Sites can bypass security checks on permissions to install lightweight themes in Firefox before 60.0 and Thunderbird before 52.8, by manipulating the...
CVE-2018-5162 Medium Yes Information disclosure
A security issue has been found in Thunderbird before 52.8, where plaintext of decrypted emails can leak through the src attribute of remote images, or links.
CVE-2018-5161 Medium Yes Denial of service
A security issue has been found in Thunderbird before 52.8, where crafted message headers can cause a Thunderbird process to hang on receiving the message.
CVE-2018-5159 High Yes Arbitrary code execution
An integer overflow vulnerability has been found in the Skia library used in Firefox < 60.0 and Thunderbird < 52.8, due to 32-bit integer use in an array...
CVE-2018-5155 High Yes Arbitrary code execution
A use-after-free vulnerability has been found in Firefox < 60.0 and Thunderbird < 52.8, while adjusting layout during SVG animations with text paths.
CVE-2018-5154 High Yes Arbitrary code execution
A use-after-free vulnerability has been found in Firefox < 60.0 and Thunderbird < 52.8, while enumerating attributes during SVG animations with clip paths.
CVE-2018-5150 Critical Yes Arbitrary code execution
Several memory safety bugs have been found in Firefox before 60.0 and Thunderbird before 52.8. Some of these bugs showed evidence of memory corruption and...
Date Advisory Package Description
21 May 2018 ASA-201805-21 thunderbird multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/