Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2019.1906 Thunderbird updated in Debian 8 28 May 2019 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Mozilla Thunderbird Publisher: Debian Operating System: Debian GNU/Linux 8 Impact/Access: Execute Arbitrary Code/Commands -- Remote with User Interaction Cross-site Scripting -- Remote with User Interaction Denial of Service -- Remote with User Interaction Access Confidential Data -- Remote with User Interaction Reduced Security -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2019-11698 CVE-2019-11693 CVE-2019-11692 CVE-2019-11691 CVE-2019-9820 CVE-2019-9819 CVE-2019-9817 CVE-2019-9816 CVE-2019-9800 CVE-2019-9797 CVE-2019-7317 CVE-2019-5798 CVE-2018-18511 Reference: ASB-2019.0082 ESB-2019.1877 ESB-2019.0598 Original Bulletin: https://lists.debian.org/debian-lts-announce/2019/05/msg00038.html - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Package : thunderbird Version : 1:60.7.0-1~deb8u1 CVE ID : CVE-2018-18511 CVE-2019-5798 CVE-2019-7317 CVE-2019-9797 CVE-2019-9800 CVE-2019-9816 CVE-2019-9817 CVE-2019-9819 CVE-2019-9820 CVE-2019-11691 CVE-2019-11692 CVE-2019-11693 CVE-2019-11698 Multiple security issues have been found in Thunderbird: Multiple vulnerabilities may lead to the execution of arbitrary code or denial of service. For Debian 8 "Jessie", these problems have been fixed in version 1:60.7.0-1~deb8u1. We recommend that you upgrade your thunderbird packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAlzro/kACgkQnUbEiOQ2 gwKriRAAh8FFNQt0oDiWd+OPwn38noQ7w0UOsGsf9t5Hhy/eLK4kmUIeJ1j2HhiL SwHeq32Nwb3W0rTGoETSUCY+iHPAl0VVlshxO60rAlC9gPb3us18x5yqIqw5vWVa FnBxF4CeClLleChfPOBV14kyaWGGxkY2xRJJbVKca0qzKwOErELgX+NOCteaRWwx Z3JucZ6h8iN32NdimVj3gVXL+G6omi314KBelluc03LbATvIMUnUQ67S+iXK8cFc FGvZ11rm60pKHRI1apL878MZO0KGT/Mdk679cvnmSqrnLw3co05dNu+mnys0Uieq gU800oaabTC2tFsj2JzlSx1cUgdEMKafA8+8AIUnKep5EfdlarjEod0+TilEhqfo KfKCv/+oyDqZPqfhuO0grIdlKDpj162W+aSmlR2LOlHmPBzwDt5MXaS0G5R3L3iO 1m5UijOIi2qjHQ+pwP2Gdoe6zQI1iUJXbpR8rGR4WefURz6LW+qzjNqKo+0sq7Ha Z76zkB/4K/dAlt6U2W02KSUzeZiHY+Gr4oCnhjMhLXIjQudKuqnW/rqebia+vV1e uCE14SVtVpyj6rERQkpb05n5GEAFEAtYY7WlNMIi5xhAsgjPAHzFMYDRjjhmjZRS Dy0cB0K4bRAEw4zIVT10trBtksZCgyko/qHi4EwMg5RU3dSBChg= =42Ni - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXOxiOGaOgq3Tt24GAQglWg/9ElH0MyFp5mReJrC2cWY7/al19Jg9R4Pe x48BEPVEAqIcDlCS/USw7C19gpLrghzaOtHdrJUUGNJxMJJT1npJ/Gp77PvoTxpW /a8MDkMalB1AcKRDxJgVFDPscD+wEpU1R9d1L2fACUhLpHvjF083R2FkLAMk6djs Ob0eGyl6v2Cq51UyDx6VFF89WC60/j7Cwk4Vt49ljd4P1FrBPHFyd6nWOuryCiJh IG9qcTGM/H1l2A5vzJpgma58fsc+kAErbDQoLMjYygwjdy/shwezhiH1I8FEucqE FSNudslgxNwlRWKQuhsRW9rj/YSsXiQ+iCouetyCoUdvL0zVvzo/iygXX5Leibbr INby6qQ2ymq/O5rVUAhHeRQ2OUoM97KVhSGCV2KVDrRvFCt1PZXqlOTjnetKHOiH ycWryvclcenolGuY551+kNFxTIoIn9oGWLx8C8ZTIGXUDEmEQbhOS8c3BpwAT2lF 7JJ+K9ue8gYXE3q2eC+qNUy5tCAaNfZj/+Qrtk+Dj4tg81TT+7MzfdlPZnzY20BC C3gwBBUdEPRDy+k5c/XdPsfvdy6fSlTESkvAcQONCz4IldGIhY2AeWIrgIygle7n LgWH237hV7czYwNd97+ty9vdl1XGptivRZux9sLdEQdRZPqxd8B3m5LCU6G1+RC1 h3lLJNsTFUY= =7LXl -----END PGP SIGNATURE-----