Lucene search

K
altlinuxHttps://packages.altlinux.org/en/sisyphus/security/C4BF398E921E5A822EB4588220CC3C11
HistoryAug 13, 2018 - 12:00 a.m.

Security fix for the ALT Linux 10 package thunderbird version 60.0-alt1

2018-08-1300:00:00
https://packages.altlinux.org/en/sisyphus/security/
packages.altlinux.org
9

0.33 Low

EPSS

Percentile

97.1%

Aug. 13, 2018 Andrey Cherepanov 60.0-alt1

- New version (60.0).
- Enigmail 2.0.8.
- Fixes:
  + CVE-2018-12359 Buffer overflow using computed size of canvas element
  + CVE-2018-12360 Use-after-free when using focus()
  + CVE-2018-12361 Integer overflow in SwizzleData
  + CVE-2018-12362 Integer overflow in SSSE3 scaler
  + CVE-2018-5156 Media recorder segmentation fault when track type is changed during capture
  + CVE-2018-12363 Use-after-free when appending DOM nodes
  + CVE-2018-12364 CSRF attacks through 307 redirects and NPAPI plugins
  + CVE-2018-12365 Compromised IPC child process can list local filenames
  + CVE-2018-12371 Integer overflow in Skia library during edge builder allocation
  + CVE-2018-12366 Invalid data handling during QCMS transformations
  + CVE-2018-12367 Timing attack mitigation of PerformanceNavigationTiming
  + CVE-2018-12368 No warning when opening executable SettingContent-ms files
  + CVE-2018-5187 Memory safety bugs fixed in Firefox 61, Firefox ESR 60.1, and Thunderbird 60
  + CVE-2018-5188 Memory safety bugs fixed in Firefox 61, Firefox ESR 60.1, Firefox ESR 52.9, and Thunderbird 60