Thunderbird is vulnerable to timing attack. The vulnerability existed because the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals but PerformanceNavigationTiming was not adjusted and it was found that it could be used as a precision timer.
CPE | Name | Operator | Version |
---|---|---|---|
thunderbird:stretch | eq | 1:52.9.1-1~deb9u1 | |
thunderbird:stretch | eq | 1:52.9.1-1~deb9u1 |
www.securityfocus.com/bid/104561
www.securitytracker.com/id/1041193
bugzilla.mozilla.org/show_bug.cgi?id=1462891
lists.debian.org/debian-lts-announce/2018/11/msg00011.html
security-tracker.debian.org/tracker/CVE-2018-12367
security.gentoo.org/glsa/201810-01
security.gentoo.org/glsa/201811-13
usn.ubuntu.com/3705-1/
www.debian.org/security/2018/dsa-4295
www.mozilla.org/security/advisories/mfsa2018-15/
www.mozilla.org/security/advisories/mfsa2018-16/
www.mozilla.org/security/advisories/mfsa2018-19/