Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2020.0300
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2020-0300)
Summary:The remote host is missing an update for the 'thunderbird, thunderbird-l10n' package(s) announced via the MGASA-2020-0300 advisory.
Description:Summary:
The remote host is missing an update for the 'thunderbird, thunderbird-l10n' package(s) announced via the MGASA-2020-0300 advisory.

Vulnerability Insight:
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server
sends a PREAUTH response, then Thunderbird will continue with an unencrypted
connection, causing email data to be sent without protection (CVE-2020-12398).

When browsing a malicious page, a race condition in our SharedWorkerService
could occur and lead to a potentially exploitable crash due to a use-after-free
(CVE-2020-12405).

Mozilla developer Iain Ireland discovered a missing type check during unboxed
objects removal, resulting in a crash due to type confusion with NativeTypes. We
presume that with enough effort that it could be exploited to run arbitrary code
(CVE-2020-12406).

Mozilla developers Tom Tung and Karl Tomlinson reported memory safety bugs
present in Firefox ESR 68.8. Some of these bugs showed evidence of memory
corruption and we presume that with enough effort some of these could have been
exploited to run arbitrary code (CVE-2020-12410).

Manipulating individual parts of a URL object could have caused an
out-of-bounds read, leaking process memory to malicious JavaScript
(CVE-2020-12418).

When processing callbacks that occurred during window flushing in the parent
process, the associated window may die, causing a use-after-free in
nsGlobalWindowInner. This could have led to memory corruption and a
potentially exploitable crash (CVE-2020-12419).

When trying to connect to a STUN server, a race condition could have caused a
use-after-free of a pointer, leading to memory corruption and a potentially
exploitable crash (CVE-2020-12420).

If an attacker intercepts Thunderbird's initial attempt to perform automatic
account setup using the Microsoft Exchange autodiscovery mechanism, and the
attacker sends a crafted response, then Thunderbird sends username and
password over https to a server controlled by the attacker (MFSA-2020-0001).

When performing add-on updates, certificate chains terminating in
non-built-in-roots were rejected (even if they were legitimately added by an
administrator.) This could have caused add-ons to become out-of-date silently
without notification to the user (CVE-2020-12421).

Affected Software/OS:
'thunderbird, thunderbird-l10n' package(s) on Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-12398
https://bugzilla.mozilla.org/show_bug.cgi?id=1613623
https://www.mozilla.org/security/advisories/mfsa2020-22/
https://usn.ubuntu.com/4421-1/
Common Vulnerability Exposure (CVE) ID: CVE-2020-12405
https://bugzilla.mozilla.org/show_bug.cgi?id=1631618
https://www.mozilla.org/security/advisories/mfsa2020-20/
https://www.mozilla.org/security/advisories/mfsa2020-21/
Common Vulnerability Exposure (CVE) ID: CVE-2020-12406
https://bugzilla.mozilla.org/show_bug.cgi?id=1639590
Common Vulnerability Exposure (CVE) ID: CVE-2020-12410
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1619305%2C1632717
Common Vulnerability Exposure (CVE) ID: CVE-2020-12418
https://security.gentoo.org/glsa/202007-09
https://security.gentoo.org/glsa/202007-10
https://bugzilla.mozilla.org/show_bug.cgi?id=1641303
https://www.mozilla.org/security/advisories/mfsa2020-24/
https://www.mozilla.org/security/advisories/mfsa2020-25/
https://www.mozilla.org/security/advisories/mfsa2020-26/
SuSE Security Announcement: openSUSE-SU-2020:0967 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html
SuSE Security Announcement: openSUSE-SU-2020:0982 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00026.html
SuSE Security Announcement: openSUSE-SU-2020:0983 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html
SuSE Security Announcement: openSUSE-SU-2020:1017 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-12419
https://bugzilla.mozilla.org/show_bug.cgi?id=1643874
Common Vulnerability Exposure (CVE) ID: CVE-2020-12420
https://bugzilla.mozilla.org/show_bug.cgi?id=1643437
Common Vulnerability Exposure (CVE) ID: CVE-2020-12421
https://bugzilla.mozilla.org/show_bug.cgi?id=1308251
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.