-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2020.1630
                 [DLA 2206-1] thunderbird security update
                                11 May 2020

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           thunderbird
Publisher:         Debian
Operating System:  Debian GNU/Linux 8
                   Debian GNU/Linux 9
                   Debian GNU/Linux 10
Impact/Access:     Execute Arbitrary Code/Commands -- Remote with User Interaction
                   Denial of Service               -- Remote with User Interaction
                   Provide Misleading Information  -- Remote with User Interaction
                   Access Confidential Data        -- Remote with User Interaction
                   Reduced Security                -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-12397 CVE-2020-12395 CVE-2020-12392
                   CVE-2020-12387 CVE-2020-6831 

Reference:         ESB-2020.1602

Original Bulletin: 
   https://www.debian.org/security/2020/dsa-4683
   https://www.debian.org/lts/security/2020/dla-2206

Comment: This bulletin contains two (2) Debian security advisories.

- --------------------------BEGIN INCLUDED TEXT--------------------

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-4683-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
May 08, 2020                          https://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : thunderbird
CVE ID         : CVE-2020-6831 CVE-2020-12387 CVE-2020-12392 CVE-2020-12395 
                 CVE-2020-12397

Multiple security issues have been found in Thunderbird which could
result in spoofing the displayed sender email address, denial of service
or potentially the execution of arbitrary code.

For the oldstable distribution (stretch), these problems have been fixed
in version 1:68.8.0-1~deb9u1.

For the stable distribution (buster), these problems have been fixed in
version 1:68.8.0-1~deb10u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl61rrsACgkQEMKTtsN8
TjafRhAArjnN6ZoNxrBCmoIuJfLR7eT4q3Gch/QE/mSG0u8OPIPFtKg/THbRJgWE
0+w1Ml5C1sRWR2ggQBjS+ho7mvGRFzL1CEEnTWn9nls73M/Aqlrdoy5KJjxs+XZj
vr/5bYfZNjz6y8ruAl2P/v8j3Q5yZxFlXqT2JYyegc0kvlUZAezkROFu1vWV0PRz
qibDQPxWS3T8aMi2WWkejZmHN9nJSJ9rQBY5ZWzcAiDxQCm4x1bism3JXG1ZYTC0
UyU//38okYc+mavyjSENQd/3fF20SJJheFjev5GCsZhG+2wRPl9ZX1mEEsqHDwID
L8xHS0AyklE/Sxip9HA9HPXqRCnr2CXYOjOGMscoXON1YLhftKKRrj+juBWKBJ3p
xmXWH/YKswG4YdU6Lwo+tSvXhUXseCuA6ZY9w31M4h78fnyztZNH2xo15n/H4bvG
k4AgfM9EQSqWq7A1+l18IyhsK0V6EazeaVAZcCzeL8KeIOR4op0rzfjsD9jzpHUA
B6Gj3e75mdLDjdqKd/XhrZ3G2yfWeXxmFnBk1A3CEiMxiF6P8DbHSejYFPyuesZ7
MsdUYTjQ/6Hipbc70KvQiFD1ELldcLv/VsipL8bv7ZSdkyH/8CWdmSEjccPhhXuj
lEJskOuvTPyyfaaWTmnQkKamWi9K3C44KhZy7zVP57FtKSjok7g==yRB7
- -----END PGP SIGNATURE-----

- -----------------------------------------------------------------------------


Package        : thunderbird
Version        : 1:68.8.0-1~deb8u1
CVE ID         : CVE-2020-6831 CVE-2020-12387 CVE-2020-12392 CVE-2020-12395
                 CVE-2020-12397


Multiple security issues have been found in Thunderbird which could
result in spoofing the displayed sender email address, denial of service
or potentially the execution of arbitrary code.

For Debian 8 "Jessie", these problems have been fixed in version
1:68.8.0-1~deb8u1.

We recommend that you upgrade your thunderbird packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

- -----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEz9ERzDttUsU/BH8iLNd4Xt2nsg8FAl626tkACgkQLNd4Xt2n
sg86gA/9HVmOz46Xr/so5HVe3v1V6bg04jWwirI8XorUTbYr1Zo540cDiORp2tUg
LHj3NcSJ8Li+KYDGl50CAF/tq8rNbJHnrz2rQrlAE067wxd9DqgTDrM9OQHC/KDn
dQD8JtIsc3Do8nCoQjTMJ6Xw1OS6TL8kOWrAXPaVmq59wQgYAtGb1AiQDarAPWuK
mY7jdrk9wtoeWJm3zm/KvNPC11nGhygLnSeuLMqS3ifwBtt0ykhxOt5LUtZU2Jll
CHrrp4MQCl1R7g8dnu5NQwGNXOo5EHQ1XezpNW7lLkJhDcmtfyMeygdAnRBVZRIS
33hKY0UTyznYzZg0UC4A3C71MUfImfc4+VuVhw3yacc0sDQSj0qRC3xP1ToUY6hC
VnHWaiEzRGsb3fu26pRxWOFzYDfG/gSrXW0yfA5d58q6kjXUVFBRKpM7N67jKgb1
K4jaQCC/YvtpMsV1rg0733MZHHiE94WN35Hh/b/BFFJYaqm+b/9+GBIA+Yq44Jaf
zQpZ1a8ZMEiP+mCLF60Y8dVUse01izSUEVYp3c00SEQxEtACUbCSD7Cc7/rsfZAE
V/IDsB1BX+wzWpSYA/aPZRwE5D0ZJjeKhm8oBeQtyzqgnafB8+0ksciwRyAejOtf
jqRBPpx+WK3Z+tUYClvVw/0dgC8zIKRaFqleq8isaHTxZtneu4E=
=elzO
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXribzWaOgq3Tt24GAQgZbxAA1vg4aZxBk6Z0ufw9n5Jhr5odcAJ9EenQ
F4bJBKka+yJfAx8keHkBc9LvlEaXG8dCW6rHLLWdW9maRzFzP8CL9paFM6AqWz/l
yhv28i32POx/3hp+qWkkpP7Rpk64ttJ8vrfkGnLZHglJj9s1RwV2z2LA/8Mj9fyd
cncF9ec1sx+4iGCX1Z33OAM146J8gq5gxoWdCOPvUVEIfWNRTadrtIwWMoFsixWU
9NDJF7Pki5IZG+2W7s3YK4HBG8OLXBNf9z7YIeErhdoMOH8rqkIdf55Nf5iow+bM
BzRm33Fe6DNQaiqURG6x1rbPo34FrnGbgetY3vQrF5w00HfvpF1Nlw+YVRHr6y1I
Pk2jatQXw5mKVEkqOet+GztyM1J6DykvHywuBlmuNyzyJJmXjVzzc6P/c1trHQEx
y8cHH04D3usysu44K6un7hm/B66w9vPOfEyWTfRgqPAZheHE6scVqkBgAxXD1/vj
azxB0gFBegQyd8jVHX00nFDD03141dDSiTK6mlDjfNPqsv8y56ldDhnu6nVPMdda
oBEBgEn3383cWBmHjYyS+85G/kLUzOydKcTy1N6NsvlkGyt+/mhhGyw+nyf1WPO6
xFZCv8ciLTvdTR9r2Dij1DmgACxQ/NkPlk02cF2bMEEKHbvRYrDS8L0CLefrjlz1
5zIpSc5/RMM=
=orOK
-----END PGP SIGNATURE-----