MGASA-2017-0180

Source
https://advisories.mageia.org/MGASA-2017-0180.html
Import Source
https://advisories.mageia.org/MGASA-2017-0180.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2017-0180
Related
Published
2017-06-19T07:44:03Z
Modified
2017-06-19T07:30:03Z
Summary
Updated thunderbird packages fix security vulnerability and bugs
Details
  • Use-after-free using destroyed node when regenerating trees (CVE-2017-5472).
  • Use-after-free during docshell reloading (CVE-2017-7749).
  • Use-after-free with track elements (CVE-2017-7750).
  • Use-after-free with content viewer listeners (CVE-2017-7751).
  • Use-after-free with IME input (CVE-2017-7752).
  • Out-of-bounds read in WebGL with ImageInfo object (CVE-2017-7754).
  • Use-after-free and use-after-scope logging XHR header errors (CVE-2017-7756).
  • Use-after-free in IndexedDB (CVE-2017-7757).
  • Vulnerabilities in the Graphite 2 library (CVE-2017-7778).
  • Out-of-bounds read in Opus encoder (CVE-2017-7758).
  • Mac fonts render some unicode characters as spaces (CVE-2017-7763).
  • Domain spoofing with combination of Canadian Syllabics and other unicode blocks (CVE-2017-7764).
  • Mark of the Web bypass when saving executable files (CVE-2017-7765).
  • Memory safety bugs fixed in Firefox 54 and Firefox ESR 52.2, and Thunderbird 52.2 (CVE-2017-5470).
  • plus various bug fixes.
References
Credits

Affected packages

Mageia:5 / thunderbird

Package

Name
thunderbird
Purl
pkg:rpm/mageia/thunderbird?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
52.2.0-1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / thunderbird-l10n

Package

Name
thunderbird-l10n
Purl
pkg:rpm/mageia/thunderbird-l10n?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
52.2.0-1.mga5

Ecosystem specific

{
    "section": "core"
}