[MFSA-2018-04] Security vulnerabilities fixed in Thunderbird 52.6

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 10

In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.

  • CVE-2018-5089: Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 (critical)
    Mozilla developers and community members Christian Holler, Jason Kratzer, Marcia Knous, Nathan Froyd, Oriol Brufau, Ronald Crane, Randell Jesup, Tyson Smith, Emilio Cobos Álvarez, Ryan VanderMeulen, Sebastian Hengst, Karl Tomlinson, Xidorn Quan, Ludovic Hirlimann, and Jason Orendorff reported memory safety bugs present in Firefox 57, Firefox ESR 52.5, and Thunderbird 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.

  • CVE-2018-5095: Integer overflow in Skia library during edge builder allocation (high)
    An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash.

  • CVE-2018-5096: Use-after-free while editing form elements (high)
    A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash.

  • CVE-2018-5097: Use-after-free when source document is manipulated during XSLT (high)
    A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the transformation. This results in a potentially exploitable crash.

  • CVE-2018-5098: Use-after-free while manipulating form input elements (high)
    A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash.

  • CVE-2018-5099: Use-after-free with widget listener (high)
    A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when these references are used.

  • CVE-2018-5102: Use-after-free in HTML media elements (high)
    A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash.

  • CVE-2018-5103: Use-after-free during mouse event handling (high)
    A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash.

  • CVE-2018-5104: Use-after-free during font face manipulation (high)
    A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash.

  • CVE-2018-5117: URL spoofing with right-to-left text aligned left-to-right (moderate)
    If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded.

Package Affected Version
pkg:mozilla/Thunderbird < 52.6
Package Fixed Version
pkg:mozilla/Thunderbird = 52.6
Source # ID Name URL
Bugzilla 1412420 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1412420
Bugzilla 1426783 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1426783
Bugzilla 1422389 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1422389
Bugzilla 1415598 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1415598
Bugzilla 1410134 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1410134
Bugzilla 1408017 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1408017
Bugzilla 1224396 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1224396
Bugzilla 1382366 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1382366
Bugzilla 1415582 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1415582
Bugzilla 1417797 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1417797
Bugzilla 1409951 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1409951
Bugzilla 1414452 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1414452
Bugzilla 1428589 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1428589
Bugzilla 1425780 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1425780
Bugzilla 1399520 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1399520
Bugzilla 1418854 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1418854
Bugzilla 1408276 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1408276
Bugzilla 1412145 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1412145
Bugzilla 1331209 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1331209
Bugzilla 1425612 Memory safety bugs fixed in Firefox 58, Firefox ESR 52.6, and Thunderbird 52.6 https://bugzilla.mozilla.org/show_bug.cgi?id=1425612
Bugzilla 1418447 https://bugzilla.mozilla.org/show_bug.cgi?id=1418447
Bugzilla 1418922 https://bugzilla.mozilla.org/show_bug.cgi?id=1418922
Bugzilla 1387427 https://bugzilla.mozilla.org/show_bug.cgi?id=1387427
Bugzilla 1399400 https://bugzilla.mozilla.org/show_bug.cgi?id=1399400
Bugzilla 1416878 https://bugzilla.mozilla.org/show_bug.cgi?id=1416878
Bugzilla 1419363 https://bugzilla.mozilla.org/show_bug.cgi?id=1419363
Bugzilla 1423159 https://bugzilla.mozilla.org/show_bug.cgi?id=1423159
Bugzilla 1425000 https://bugzilla.mozilla.org/show_bug.cgi?id=1425000
Bugzilla 1395508 https://bugzilla.mozilla.org/show_bug.cgi?id=1395508
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:mozilla/Thunderbird Thunderbird < 52.6
Fixed pkg:mozilla/Thunderbird Thunderbird = 52.6
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...