Multiple vulnerabilities in Mozilla Thunderbird

Published: 2019-06-14 08:32:13 | Updated: 2019-06-14
Severity High
Patch available YES
Number of vulnerabilities 4
CVE ID CVE-2019-11703
CVE-2019-11704
CVE-2019-11705
CVE-2019-11706
CVSSv3 7.7 [CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
7.7 [CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
7.7 [CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
3.8 [CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]
CWE ID CWE-122
CWE-121
CWE-843
Exploitation vector Network
Public exploit N/A
Vulnerable software Mozilla Thunderbird
Vulnerable software versions Mozilla Thunderbird 60.7.0
Mozilla Thunderbird 60.6.1
Mozilla Thunderbird 60.6.0

Show more

Vendor URL Mozilla

Security Advisory

1) Heap-based buffer overflow

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the iCal implementation in parser_get_next_char function in icalparser.c. A remote attacker can send a specially crafted email, trigger heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Remediation

Install updates from vendor's website.

External links

https://www.mozilla.org/en-US/security/advisories/mfsa2019-17/

2) Heap-based buffer overflow

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the iCal implementation in icalmemory_strdup_and_dequote function in icalvalue.c. A remote attacker can create a specially crafted email, trigger heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Remediation

Install updates from vendor's website.

External links

https://www.mozilla.org/en-US/security/advisories/mfsa2019-17/

3) Stack-based buffer overflow

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within iCal implementation in icalrecur_add_bydayrules function in icalrecur.c. A remote unauthenticated attacker can create a specially crafted email, trigger stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Remediation

Install updates from vendor's website.

External links

https://www.mozilla.org/en-US/security/advisories/mfsa2019-17/

4) Type Confusion

Description

The vulnerability allows a remote attacker to perform denial of service (DoS) attack.

The vulnerability exists due to a type confusion error within the iCal implementation in icaltimezone_get_vtimezone_properties function in icalproperty.c. A remote attacker can create a specially crafted email with malformed timezone data, trigger a type confusion error and crash the application.


Remediation

Install updates from vendor's website.

External links

https://www.mozilla.org/en-US/security/advisories/mfsa2019-17/

Back to List