![]() |
Startseite ▼ Bookkeeping
Online ▼ Sicherheits
Überprüfungs ▼
Verwaltetes
DNS ▼
Info
Bestellen/Erneuern
FAQ
AUP
Dynamic DNS Clients
Domaine konfigurieren Dyanmic DNS Update Password Netzwerk
Überwachung ▼
Enterprise
Erweiterte
Standard
Gratis Test
FAQ
Preis/Funktionszusammenfassung
Bestellen
Beispiele
Konfigurieren/Status Alarm Profile | ||
Test Kennung: | 1.3.6.1.4.1.25623.1.1.10.2020.0300 |
Kategorie: | Mageia Linux Local Security Checks |
Titel: | Mageia: Security Advisory (MGASA-2020-0300) |
Zusammenfassung: | The remote host is missing an update for the 'thunderbird, thunderbird-l10n' package(s) announced via the MGASA-2020-0300 advisory. |
Beschreibung: | Summary: The remote host is missing an update for the 'thunderbird, thunderbird-l10n' package(s) announced via the MGASA-2020-0300 advisory. Vulnerability Insight: If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection (CVE-2020-12398). When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash due to a use-after-free (CVE-2020-12405). Mozilla developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash due to type confusion with NativeTypes. We presume that with enough effort that it could be exploited to run arbitrary code (CVE-2020-12406). Mozilla developers Tom Tung and Karl Tomlinson reported memory safety bugs present in Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code (CVE-2020-12410). Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript (CVE-2020-12418). When processing callbacks that occurred during window flushing in the parent process, the associated window may die, causing a use-after-free in nsGlobalWindowInner. This could have led to memory corruption and a potentially exploitable crash (CVE-2020-12419). When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash (CVE-2020-12420). If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker (MFSA-2020-0001). When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user (CVE-2020-12421). Affected Software/OS: 'thunderbird, thunderbird-l10n' package(s) on Mageia 7. Solution: Please install the updated package(s). CVSS Score: 9.3 CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C |
Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2020-12398 https://bugzilla.mozilla.org/show_bug.cgi?id=1613623 https://www.mozilla.org/security/advisories/mfsa2020-22/ https://usn.ubuntu.com/4421-1/ Common Vulnerability Exposure (CVE) ID: CVE-2020-12405 https://bugzilla.mozilla.org/show_bug.cgi?id=1631618 https://www.mozilla.org/security/advisories/mfsa2020-20/ https://www.mozilla.org/security/advisories/mfsa2020-21/ Common Vulnerability Exposure (CVE) ID: CVE-2020-12406 https://bugzilla.mozilla.org/show_bug.cgi?id=1639590 Common Vulnerability Exposure (CVE) ID: CVE-2020-12410 https://bugzilla.mozilla.org/buglist.cgi?bug_id=1619305%2C1632717 Common Vulnerability Exposure (CVE) ID: CVE-2020-12418 https://security.gentoo.org/glsa/202007-09 https://security.gentoo.org/glsa/202007-10 https://bugzilla.mozilla.org/show_bug.cgi?id=1641303 https://www.mozilla.org/security/advisories/mfsa2020-24/ https://www.mozilla.org/security/advisories/mfsa2020-25/ https://www.mozilla.org/security/advisories/mfsa2020-26/ SuSE Security Announcement: openSUSE-SU-2020:0967 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html SuSE Security Announcement: openSUSE-SU-2020:0982 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html SuSE Security Announcement: openSUSE-SU-2020:0983 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html SuSE Security Announcement: openSUSE-SU-2020:1017 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html Common Vulnerability Exposure (CVE) ID: CVE-2020-12419 https://bugzilla.mozilla.org/show_bug.cgi?id=1643874 Common Vulnerability Exposure (CVE) ID: CVE-2020-12420 https://bugzilla.mozilla.org/show_bug.cgi?id=1643437 Common Vulnerability Exposure (CVE) ID: CVE-2020-12421 https://bugzilla.mozilla.org/show_bug.cgi?id=1308251 |
Copyright | Copyright (C) 2022 Greenbone AG |
Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |