Ubuntu update for Thunderbird



Published: 2019-02-27
Risk High
Patch available YES
Number of vulnerabilities 7
CVE-ID CVE-2016-5824
CVE-2018-18356
CVE-2018-18500
CVE-2019-5785
CVE-2018-18501
CVE-2018-18505
CVE-2018-18509
CWE-ID CWE-416
CWE-190
CWE-119
CWE-264
CWE-451
Exploitation vector Network
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software
Subscribe
thunderbird (Ubuntu package)
Operating systems & Components / Operating system package or component

Vendor Canonical Ltd.

Security Bulletin

This security bulletin contains information about 7 vulnerabilities.

1) Use-after-free

EUVDB-ID: #VU17266

Risk: Low

CVSSv3.1: 5.9 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C]

CVE-ID: CVE-2016-5824

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform denial of service attack.

The vulnerability exists due to a use-after-free error when processing ics Calendar files. A remote attackers can trick the victim to open a specially crafted calendar file, trigger user-after-free error and crash the affected application.

Mitigation

Update the affected packages.

Ubuntu 18.10
thunderbird - 1:60.5.1+build2-0ubuntu0.18.10.1
Ubuntu 18.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.18.04.1
Ubuntu 16.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.16.04.1
Ubuntu 14.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.14.04.1

Vulnerable software versions

thunderbird (Ubuntu package): 1:24.5.0+build1-0ubuntu0.14.04.1 - 1:60.4.0+build2-0ubuntu0.18.10.1

External links

http://usn.ubuntu.com/3897-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

2) Use-after-free error

EUVDB-ID: #VU16255

Risk: Low

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2018-18356

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to use-after-free error in Skia when handling malicious input. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and cause the browser to crash.

Mitigation

Update the affected packages.

Ubuntu 18.10
thunderbird - 1:60.5.1+build2-0ubuntu0.18.10.1
Ubuntu 18.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.18.04.1
Ubuntu 16.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.16.04.1
Ubuntu 14.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.14.04.1

Vulnerable software versions

thunderbird (Ubuntu package): 1:24.5.0+build1-0ubuntu0.14.04.1 - 1:60.4.0+build2-0ubuntu0.18.10.1

External links

http://usn.ubuntu.com/3897-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Use-after-free

EUVDB-ID: #VU17258

Risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2018-18500

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when HTML5 stream in concert with custom HTML elements. A remote attacker can create a specially crafted web page. trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.

Mitigation

Update the affected packages.

Ubuntu 18.10
thunderbird - 1:60.5.1+build2-0ubuntu0.18.10.1
Ubuntu 18.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.18.04.1
Ubuntu 16.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.16.04.1
Ubuntu 14.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.14.04.1

Vulnerable software versions

thunderbird (Ubuntu package): 1:24.5.0+build1-0ubuntu0.14.04.1 - 1:60.4.0+build2-0ubuntu0.18.10.1

External links

http://usn.ubuntu.com/3897-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Integer overflow

EUVDB-ID: #VU17653

Risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-5785

CWE-ID: CWE-190 - Integer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the Skia library. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected packages.

Ubuntu 18.10
thunderbird - 1:60.5.1+build2-0ubuntu0.18.10.1
Ubuntu 18.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.18.04.1
Ubuntu 16.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.16.04.1
Ubuntu 14.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.14.04.1

Vulnerable software versions

thunderbird (Ubuntu package): 1:24.5.0+build1-0ubuntu0.14.04.1 - 1:60.4.0+build2-0ubuntu0.18.10.1

External links

http://usn.ubuntu.com/3897-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Buffer overflow

EUVDB-ID: #VU17262

Risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2018-18501

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected packages.

Ubuntu 18.10
thunderbird - 1:60.5.1+build2-0ubuntu0.18.10.1
Ubuntu 18.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.18.04.1
Ubuntu 16.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.16.04.1
Ubuntu 14.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.14.04.1

Vulnerable software versions

thunderbird (Ubuntu package): 1:24.5.0+build1-0ubuntu0.14.04.1 - 1:60.4.0+build2-0ubuntu0.18.10.1

External links

http://usn.ubuntu.com/3897-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU17263

Risk: Low

CVSSv3.1: 4.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2018-18505

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass imposed sandbox restrictions.

The vulnerability exists within implementation of authentication process for Inter-process Communication (IPC). This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. A remote attacker can bypass sandbox restrictions through IPC channels due to lack of message validation in the listener process.

Mitigation

Update the affected packages.

Ubuntu 18.10
thunderbird - 1:60.5.1+build2-0ubuntu0.18.10.1
Ubuntu 18.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.18.04.1
Ubuntu 16.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.16.04.1
Ubuntu 14.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.14.04.1

Vulnerable software versions

thunderbird (Ubuntu package): 1:24.5.0+build1-0ubuntu0.14.04.1 - 1:60.4.0+build2-0ubuntu0.18.10.1

External links

http://usn.ubuntu.com/3897-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) Spoofing attack

EUVDB-ID: #VU17703

Risk: Low

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2018-18509

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

Exploit availability: No

Description

The vulnerability allows a remote attacker to conduct spoofing attack.

The vulnerability exists due to a flaw during verification of certain S/MIME signatures causes emails can be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. A remote attacker can reuse a valid S/MIME signature to craft an email message with arbitrary content.

Mitigation

Update the affected packages.

Ubuntu 18.10
thunderbird - 1:60.5.1+build2-0ubuntu0.18.10.1
Ubuntu 18.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.18.04.1
Ubuntu 16.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.16.04.1
Ubuntu 14.04 LTS
thunderbird - 1:60.5.1+build2-0ubuntu0.14.04.1

Vulnerable software versions

thunderbird (Ubuntu package): 1:24.5.0+build1-0ubuntu0.14.04.1 - 1:60.4.0+build2-0ubuntu0.18.10.1

External links

http://usn.ubuntu.com/3897-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###