MGASA-2019-0129

Source
https://advisories.mageia.org/MGASA-2019-0129.html
Import Source
https://advisories.mageia.org/MGASA-2019-0129.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2019-0129
Related
Published
2019-04-05T18:12:59Z
Modified
2019-04-05T17:36:56Z
Summary
Updated thunderbird packages fix security vulnerability
Details

Use-after-free when removing in-use DOM elements. (CVE-2019-9790)

Type inference is incorrect for constructors entered through on-stack replacement with IonMonkey. (CVE-2019-9791)

IonMonkey leaks JSOPTIMIZEDOUT magic value to script. (CVE-2019-9792)

Improper bounds checks when Spectre mitigations are disabled. (CVE-2019-9793)

Command line arguments not discarded during execution. (CVE-2019-9794)

Type-confusion in IonMonkey JIT compiler. (CVE-2019-9795)

Use-after-free with SMIL animation controller. (CVE-2019-9796)

Windows programs that are not 'URL Handlers' are exposed to web content. (CVE-2019-9801)

Proxy Auto-Configuration file can define localhost access to be proxied. (CVE-2018-18506)

Memory safety bugs fixed in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. (CVE-2019-9788)

IonMonkey MArraySlice has incorrect alias information. (CVE-2019-9810)

Ionmonkey type confusion with proto mutations. (CVE-2019-9813)

References
Credits

Affected packages

Mageia:6 / thunderbird

Package

Name
thunderbird
Purl
pkg:rpm/mageia/thunderbird?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
60.6.1-1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / thunderbird-l10n

Package

Name
thunderbird-l10n
Purl
pkg:rpm/mageia/thunderbird-l10n?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
60.6.1-1.mga6

Ecosystem specific

{
    "section": "core"
}