Mozilla Thunderbird < 60.2.1 Multiple Vulnerabilities

Medium Nessus Plugin ID 117939

Synopsis

A web browser installed on the remote Windows host is affected by multiple vulnerabilities.

Description

The version of Mozilla Thunderbird installed on the remote Windows host is prior to 60.2.1. It is, therefore, affected by multiple vulnerabilities as noted in Mozilla Thunderbird stable channel update release notes for 2018/10/04. Please refer to the release notes for additional information. Note that Nessus has not attempted to exploit these issues but has instead relied only on the application's self- reported version number.

Solution

Upgrade to Mozilla Thunderbird version 60.2.1 or later.

See Also

http://www.nessus.org/u?eeb4654f

http://www.nessus.org/u?20fb56d5

http://www.nessus.org/u?0ba771ab

http://www.nessus.org/u?ec8a52cc

http://www.nessus.org/u?729f9359

http://www.nessus.org/u?1de4cab5

http://www.nessus.org/u?c5d40321

http://www.nessus.org/u?2e15e66a

http://www.nessus.org/u?71d5c763

http://www.nessus.org/u?0410b02e

http://www.nessus.org/u?c939fbe7

http://www.nessus.org/u?06cc0e92

http://www.nessus.org/u?635f0fa0

http://www.nessus.org/u?4376815f

http://www.nessus.org/u?99b48daf

http://www.nessus.org/u?bc528cf5

http://www.nessus.org/u?fdfa1d66

http://www.nessus.org/u?d0c0acea

http://www.nessus.org/u?69cce0e2

http://www.nessus.org/u?ae70d802

http://www.nessus.org/u?dd5f0586

http://www.nessus.org/u?7d6a368a

http://www.nessus.org/u?61040df6

http://www.nessus.org/u?c7fa8df5

http://www.nessus.org/u?d070267e

Plugin Details

Severity: Medium

ID: 117939

File Name: mozilla_thunderbird_60_2_1.nasl

Version: 1.1

Type: local

Agent: windows

Family: Windows

Published: 2018/10/05

Modified: 2018/10/05

Dependencies: 20862

Risk Information

Risk Factor: Medium

CVSS Score Source: CVE-2017-16541

CVSSv2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSSv3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Vulnerability Information

CPE: cpe:/a:mozilla:thunderbird

Required KB Items: Mozilla/Thunderbird/Version

Patch Publication Date: 2018/10/04

Vulnerability Publication Date: 2018/10/04

Reference Information

CVE: CVE-2017-16541, CVE-2018-12376, CVE-2018-12377, CVE-2018-12378, CVE-2018-12379, CVE-2018-12383, CVE-2018-12385