-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2019.1906
                      Thunderbird updated in Debian 8
                                28 May 2019

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           Mozilla Thunderbird
Publisher:         Debian
Operating System:  Debian GNU/Linux 8
Impact/Access:     Execute Arbitrary Code/Commands -- Remote with User Interaction
                   Cross-site Scripting            -- Remote with User Interaction
                   Denial of Service               -- Remote with User Interaction
                   Access Confidential Data        -- Remote with User Interaction
                   Reduced Security                -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2019-11698 CVE-2019-11693 CVE-2019-11692
                   CVE-2019-11691 CVE-2019-9820 CVE-2019-9819
                   CVE-2019-9817 CVE-2019-9816 CVE-2019-9800
                   CVE-2019-9797 CVE-2019-7317 CVE-2019-5798
                   CVE-2018-18511  

Reference:         ASB-2019.0082
                   ESB-2019.1877
                   ESB-2019.0598

Original Bulletin: 
   https://lists.debian.org/debian-lts-announce/2019/05/msg00038.html

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : thunderbird
Version        : 1:60.7.0-1~deb8u1
CVE ID         : CVE-2018-18511 CVE-2019-5798 CVE-2019-7317 CVE-2019-9797
                 CVE-2019-9800 CVE-2019-9816 CVE-2019-9817 CVE-2019-9819
                 CVE-2019-9820 CVE-2019-11691 CVE-2019-11692 CVE-2019-11693
                 CVE-2019-11698

Multiple security issues have been found in Thunderbird: Multiple
vulnerabilities may lead to the execution of arbitrary code or denial of
service.

For Debian 8 "Jessie", these problems have been fixed in version
1:60.7.0-1~deb8u1.

We recommend that you upgrade your thunderbird packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAlzro/kACgkQnUbEiOQ2
gwKriRAAh8FFNQt0oDiWd+OPwn38noQ7w0UOsGsf9t5Hhy/eLK4kmUIeJ1j2HhiL
SwHeq32Nwb3W0rTGoETSUCY+iHPAl0VVlshxO60rAlC9gPb3us18x5yqIqw5vWVa
FnBxF4CeClLleChfPOBV14kyaWGGxkY2xRJJbVKca0qzKwOErELgX+NOCteaRWwx
Z3JucZ6h8iN32NdimVj3gVXL+G6omi314KBelluc03LbATvIMUnUQ67S+iXK8cFc
FGvZ11rm60pKHRI1apL878MZO0KGT/Mdk679cvnmSqrnLw3co05dNu+mnys0Uieq
gU800oaabTC2tFsj2JzlSx1cUgdEMKafA8+8AIUnKep5EfdlarjEod0+TilEhqfo
KfKCv/+oyDqZPqfhuO0grIdlKDpj162W+aSmlR2LOlHmPBzwDt5MXaS0G5R3L3iO
1m5UijOIi2qjHQ+pwP2Gdoe6zQI1iUJXbpR8rGR4WefURz6LW+qzjNqKo+0sq7Ha
Z76zkB/4K/dAlt6U2W02KSUzeZiHY+Gr4oCnhjMhLXIjQudKuqnW/rqebia+vV1e
uCE14SVtVpyj6rERQkpb05n5GEAFEAtYY7WlNMIi5xhAsgjPAHzFMYDRjjhmjZRS
Dy0cB0K4bRAEw4zIVT10trBtksZCgyko/qHi4EwMg5RU3dSBChg=
=42Ni
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXOxiOGaOgq3Tt24GAQglWg/9ElH0MyFp5mReJrC2cWY7/al19Jg9R4Pe
x48BEPVEAqIcDlCS/USw7C19gpLrghzaOtHdrJUUGNJxMJJT1npJ/Gp77PvoTxpW
/a8MDkMalB1AcKRDxJgVFDPscD+wEpU1R9d1L2fACUhLpHvjF083R2FkLAMk6djs
Ob0eGyl6v2Cq51UyDx6VFF89WC60/j7Cwk4Vt49ljd4P1FrBPHFyd6nWOuryCiJh
IG9qcTGM/H1l2A5vzJpgma58fsc+kAErbDQoLMjYygwjdy/shwezhiH1I8FEucqE
FSNudslgxNwlRWKQuhsRW9rj/YSsXiQ+iCouetyCoUdvL0zVvzo/iygXX5Leibbr
INby6qQ2ymq/O5rVUAhHeRQ2OUoM97KVhSGCV2KVDrRvFCt1PZXqlOTjnetKHOiH
ycWryvclcenolGuY551+kNFxTIoIn9oGWLx8C8ZTIGXUDEmEQbhOS8c3BpwAT2lF
7JJ+K9ue8gYXE3q2eC+qNUy5tCAaNfZj/+Qrtk+Dj4tg81TT+7MzfdlPZnzY20BC
C3gwBBUdEPRDy+k5c/XdPsfvdy6fSlTESkvAcQONCz4IldGIhY2AeWIrgIygle7n
LgWH237hV7czYwNd97+ty9vdl1XGptivRZux9sLdEQdRZPqxd8B3m5LCU6G1+RC1
h3lLJNsTFUY=
=7LXl
-----END PGP SIGNATURE-----