-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2021.1968
                        thunderbird security update
                                7 June 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           thunderbird
Publisher:         Debian
Operating System:  Debian GNU/Linux
Impact/Access:     Execute Arbitrary Code/Commands -- Remote with User Interaction
                   Denial of Service               -- Remote with User Interaction
                   Access Confidential Data        -- Existing Account            
                   Reduced Security                -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2021-29967 CVE-2021-29957 CVE-2021-29956

Reference:         ESB-2021.1955
                   ESB-2021.1949

Original Bulletin: 
   http://www.debian.org/security/2021/dsa-4927

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-4927-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
June 05, 2021                         https://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : thunderbird
CVE ID         : CVE-2021-29956 CVE-2021-29957 CVE-2021-29967

Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code. In adddition two security
issues were addressed in the OpenPGP support.

For the stable distribution (buster), these problems have been fixed in
version 1:78.11.0-1~deb10u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmC6rD0ACgkQEMKTtsN8
Tjavzg//S2Uxk9jji7X4W1v2Tf36KiBcLJpN8PyxiXBCbeerihWdZLHpJlcgStw4
+wFKGT4KFL1dz0aH9728x3nUxOOVIWb2jplTrEHqjQkb90nwnnBdlzpwHEjDje3c
a7rZKv0Xxa//+BeRVJQzSmqs3XZKXnoKKGS/j5HZ+hR6XWRTlyjXfk3XHReFUs38
SA5IVYYyONPng/43eOyUCjrlEuxnC1/jJAhpMz32b5tdZ5bxObh6vwRcF1M2a0Ph
I/D1t88i0idXnI6/LXuVbL0HBwF07vinPG4yydFZJEOUAUHzFwjzbTFqR1AYDV+5
XH1yu5mmc3DZgAJ7l4Nr9A7IvoYF/OAn4nxivNUnM6TQSnUVPHRFSelFZiKo53pE
3nIuWgxbyiXDSOR991IoYVGqn5wACuWOc6QU3x5Bpvj4s5TsiIMaOfLcwSiKIhBb
VowKQmEKE7DDTe7FDsOFwY7j5k6f/+uKfjijzQUQk1O9xmmdM+C+joN55Ew5Fegv
DX/6Nh4YXSK+q66QMEtsyjuHShakteI2PoBmU3MAwUMrksOvqKiINdjo9EeeR8gV
Phh9ydjQ0hhlv2OxBFwiyGA7bnyaiyx1TQis5aJ+c2kxnTA8bv86BuLc54a2e6XF
epbP9MGf25+fxjgAj+2ymnylTmfSeJEHWbSK/q1KFcv5HwClsps=
=erHX
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYL2at+NLKJtyKPYoAQhmFBAAmj3w1ei8qTDvCQFkRBpHZgsp7sbye+i+
Di4IjY7mSuSHJ/j352ZUoZEWO83iYi8AQjL4bMVSqK4NE/unRN96Aw7ihUCC0yXK
kCQlFVPYgzZaTylnYw/WO9pC72xIlX9SQxSrvscgzq1m+BToF4OrQF92QvRg8ZXJ
QP6c0PfMyZYrDNml2plpZYWSVQrczerLQquMN3tKUC67JCZbUThUIduLdn/R279z
Y1IrTWqd2j0DOsq+j6Oo4x7B+ZsQ0j+3a+AUg7g6IKSntkiJBIL20FWVqwdn3Ft4
mvszI+lLpC3AU8s0EibFVtzU8jEVV8R/Q7T6g5EnVJNibfceNORXU5HkUUEUTkrA
n6/9ucgujOf1TkvfUp8DU3LpqpRsCVAcd5IS80cWhOyzHoU27mQ468ZOjtW/MNz9
TzB0Dhc56sygIyxjLv3JzcDJg4xiU7U72/OCPHBf3hWYY17bvnO4vLTxTYBw14x6
YzMS+jduiKX07qsEds+3miJDZ6ct1yTWh3dATKKdt7bSqa1QmOyqmbl2Zw1gnGbr
cTqPWjaMfFunQugYw6Zrquvo5Vc8xo/LaX37tkU4geqapGN7QksJzEpNFIlx+BG4
tonBLNrXuhqilTpeip7qZllVrdoXz4qHMMxCvqFMl9yIYlPPGtfoi5mdUAfHI4vm
yIL93vbBxUk=
=5EMN
-----END PGP SIGNATURE-----