Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2021.1968 thunderbird security update 7 June 2021 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: thunderbird Publisher: Debian Operating System: Debian GNU/Linux Impact/Access: Execute Arbitrary Code/Commands -- Remote with User Interaction Denial of Service -- Remote with User Interaction Access Confidential Data -- Existing Account Reduced Security -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2021-29967 CVE-2021-29957 CVE-2021-29956 Reference: ESB-2021.1955 ESB-2021.1949 Original Bulletin: http://www.debian.org/security/2021/dsa-4927 - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-4927-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 05, 2021 https://www.debian.org/security/faq - - ------------------------------------------------------------------------- Package : thunderbird CVE ID : CVE-2021-29956 CVE-2021-29957 CVE-2021-29967 Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. In adddition two security issues were addressed in the OpenPGP support. For the stable distribution (buster), these problems have been fixed in version 1:78.11.0-1~deb10u1. We recommend that you upgrade your thunderbird packages. For the detailed security status of thunderbird please refer to its security tracker page at: https://security-tracker.debian.org/tracker/thunderbird Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ - -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmC6rD0ACgkQEMKTtsN8 Tjavzg//S2Uxk9jji7X4W1v2Tf36KiBcLJpN8PyxiXBCbeerihWdZLHpJlcgStw4 +wFKGT4KFL1dz0aH9728x3nUxOOVIWb2jplTrEHqjQkb90nwnnBdlzpwHEjDje3c a7rZKv0Xxa//+BeRVJQzSmqs3XZKXnoKKGS/j5HZ+hR6XWRTlyjXfk3XHReFUs38 SA5IVYYyONPng/43eOyUCjrlEuxnC1/jJAhpMz32b5tdZ5bxObh6vwRcF1M2a0Ph I/D1t88i0idXnI6/LXuVbL0HBwF07vinPG4yydFZJEOUAUHzFwjzbTFqR1AYDV+5 XH1yu5mmc3DZgAJ7l4Nr9A7IvoYF/OAn4nxivNUnM6TQSnUVPHRFSelFZiKo53pE 3nIuWgxbyiXDSOR991IoYVGqn5wACuWOc6QU3x5Bpvj4s5TsiIMaOfLcwSiKIhBb VowKQmEKE7DDTe7FDsOFwY7j5k6f/+uKfjijzQUQk1O9xmmdM+C+joN55Ew5Fegv DX/6Nh4YXSK+q66QMEtsyjuHShakteI2PoBmU3MAwUMrksOvqKiINdjo9EeeR8gV Phh9ydjQ0hhlv2OxBFwiyGA7bnyaiyx1TQis5aJ+c2kxnTA8bv86BuLc54a2e6XF epbP9MGf25+fxjgAj+2ymnylTmfSeJEHWbSK/q1KFcv5HwClsps= =erHX - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBYL2at+NLKJtyKPYoAQhmFBAAmj3w1ei8qTDvCQFkRBpHZgsp7sbye+i+ Di4IjY7mSuSHJ/j352ZUoZEWO83iYi8AQjL4bMVSqK4NE/unRN96Aw7ihUCC0yXK kCQlFVPYgzZaTylnYw/WO9pC72xIlX9SQxSrvscgzq1m+BToF4OrQF92QvRg8ZXJ QP6c0PfMyZYrDNml2plpZYWSVQrczerLQquMN3tKUC67JCZbUThUIduLdn/R279z Y1IrTWqd2j0DOsq+j6Oo4x7B+ZsQ0j+3a+AUg7g6IKSntkiJBIL20FWVqwdn3Ft4 mvszI+lLpC3AU8s0EibFVtzU8jEVV8R/Q7T6g5EnVJNibfceNORXU5HkUUEUTkrA n6/9ucgujOf1TkvfUp8DU3LpqpRsCVAcd5IS80cWhOyzHoU27mQ468ZOjtW/MNz9 TzB0Dhc56sygIyxjLv3JzcDJg4xiU7U72/OCPHBf3hWYY17bvnO4vLTxTYBw14x6 YzMS+jduiKX07qsEds+3miJDZ6ct1yTWh3dATKKdt7bSqa1QmOyqmbl2Zw1gnGbr cTqPWjaMfFunQugYw6Zrquvo5Vc8xo/LaX37tkU4geqapGN7QksJzEpNFIlx+BG4 tonBLNrXuhqilTpeip7qZllVrdoXz4qHMMxCvqFMl9yIYlPPGtfoi5mdUAfHI4vm yIL93vbBxUk= =5EMN -----END PGP SIGNATURE-----