lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20200117214041.yiapygog7agy6nu2@seger.debian.org>
Date: Fri, 17 Jan 2020 21:40:41 +0000
From: Moritz Muehlenhoff <jmm@...ian.org>
To: bugtraq@...urityfocus.com
Subject: [SECURITY] [DSA 4603-1] thunderbird security update

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4603-1                   security@...ian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
January 17, 2020                      https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : thunderbird
CVE ID         : CVE-2019-17016 CVE-2019-17017 CVE-2019-17022
                 CVE-2019-17024 CVE-2019-17026

Multiple security issues have been found in Thunderbird which could
potentially result in the execution of arbitrary code or information
disclosure.

For the oldstable distribution (stretch), these problems have been fixed
in version 1:68.4.1-1~deb9u1.

For the stable distribution (buster), these problems have been fixed in
version 1:68.4.1-1~deb10u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@...ts.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl4iKXEACgkQEMKTtsN8
TjZ8UhAAnyecGZb6V0h7FnTL/t3hLpEyaFjeml/sLiDASWj8jCDXaPpw5b4j7Ouz
p8eSbxctXPN5sMUMCPodFCExtZwbW3jlAbJSq/CCeUHV+stKZTu0a/CMhmiJQb3v
fbGqJwxAPm5iW2cuRNR2T7Wxbg1f7FdtQ6WCB0G+dozgXr245IZ7qOcSybVJym1M
ZPzSt9/qiHKF5sNe6Q/uMldz+j58N0AsJiMPTKTRL5yQJsgK2kuZ9h0lf9A0LcdX
IqOYYjAbcll/vleH5X0tAvzVd/SoPWtREmsA6TthSWm/r6U6OFE2Jf/qW5iQY5IC
Vbk20LRaV7GsnZWQMeqjRvMu8NnHzY8E+NfgnAvcBJsm2JGJ67EQ5K5U223cg+fZ
zhk2mzcvNLHTbAza6i0XNn15l/4n4x/lUennzZ4d3YJfpIy9yF8cE0XFPHKPGSJk
vZabsjjmNToXOBm+2j1LDeyx66YXOLoZVEQHbp3LICbyU/VW3SpnEVpeduxN8O++
RmiQC/q6Y+6mqeU2xzKvB8gdjuwLfTcBd9ZIiglmHiXnYLor3AUPZpiz3Qbm8up2
i8QNYzGCkyJ11OZEer20FQSiGSEwtMattzfcvXGkP9+PcbSc/sZP4J0/2v1YM+T7
d0J3RB8dGlpzSst8K8orlrIBZL+MZWlOb5dlwjeDmzD/2RdqxKI=
=+2fj
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ