Lucene search

K
altlinuxHttps://packages.altlinux.org/en/sisyphus/security/AE726B0702F835D44D5DCFBA1C81B6D2
HistoryMay 19, 2018 - 12:00 a.m.

Security fix for the ALT Linux 10 package thunderbird version 52.8.0-alt1

2018-05-1900:00:00
https://packages.altlinux.org/en/sisyphus/security/
packages.altlinux.org
12

0.122 Low

EPSS

Percentile

95.4%

May 19, 2018 Andrey Cherepanov 52.8.0-alt1

- New version (52.8.0).
- Enigmail 2.0.4.
- Fixes:
  + CVE-2018-5183 Backport critical security fixes in Skia
  + CVE-2018-5184 Full plaintext recovery in S/MIME via chosen-ciphertext attack
  + CVE-2018-5154 Use-after-free with SVG animations and clip paths
  + CVE-2018-5155 Use-after-free with SVG animations and text paths
  + CVE-2018-5159 Integer overflow and out-of-bounds write in Skia
  + CVE-2018-5161 Hang via malformed headers
  + CVE-2018-5162 Encrypted mail leaks plaintext through src attribute
  + CVE-2018-5170 Filename spoofing for external attachments
  + CVE-2018-5168 Lightweight themes can be installed without user interaction
  + CVE-2018-5178 Buffer overflow during UTF-8 to Unicode string conversion through legacy extension
  + CVE-2018-5185 Leaking plaintext through HTML forms
  + CVE-2018-5150 Memory safety bugs fixed in Firefox 60, Firefox ESR 52.8, and Thunderbird 52.8
- Build in several threads.