Scientific Linux Security Update : thunderbird on SL6.x i386/x86_64

High Nessus Plugin ID 118585

Synopsis

The remote Scientific Linux host is missing one or more security
updates.

Description

This update upgrades Thunderbird to version 60.2.1.

Security Fix(es) :

- Mozilla: Memory safety bugs fixed in Firefox 62 and
Firefox ESR 60.2 (CVE-2018-12376)

- Mozilla: Use-after-free in driver timers
(CVE-2018-12377)

- Mozilla: Use-after-free in IndexedDB (CVE-2018-12378)

- Mozilla: Proxy bypass using automount and autofs
(CVE-2017-16541)

- Mozilla: Out-of-bounds write with malicious MAR file
(CVE-2018-12379)

- Mozilla: Crash in TransportSecurityInfo due to cached
data (CVE-2018-12385)

- Mozilla: Setting a master password post-Firefox 58 does
not delete unencrypted previously stored passwords
(CVE-2018-12383)

Note: All of the above issues cannot be exploited in Thunderbird by a
specially crafted HTML mail, as JavaScript is disabled for mail
messages and cannot be enabled. They could be exploited another way in
Thunderbird, for example, when viewing the remote content of an RSS
feed.

Solution

Update the affected thunderbird and / or thunderbird-debuginfo
packages.

See Also

http://www.nessus.org/u?a52904dc

Plugin Details

Severity: High

ID: 118585

File Name: sl_20181031_thunderbird_on_SL6_x.nasl

Version: 1.3

Type: local

Agent: unix

Published: 2018/11/01

Modified: 2018/12/27

Dependencies: 12634

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS v3.0

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: x-cpe:/o:fermilab:scientific_linux

Patch Publication Date: 2018/10/31

Reference Information

CVE: CVE-2017-16541, CVE-2018-12376, CVE-2018-12377, CVE-2018-12378, CVE-2018-12379, CVE-2018-12383, CVE-2018-12385