Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2020.1296 thunderbird security update 14 April 2020 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: thunderbird Publisher: Debian Operating System: Debian GNU/Linux 9 Debian GNU/Linux 10 Impact/Access: Execute Arbitrary Code/Commands -- Remote with User Interaction Denial of Service -- Remote with User Interaction Access Confidential Data -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2020-6825 CVE-2020-6822 CVE-2020-6821 CVE-2020-6820 CVE-2020-6819 Reference: ESB-2020.1259 Original Bulletin: http://www.debian.org/security/2020/dsa-4656 - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-4656-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 13, 2020 https://www.debian.org/security/faq - - ------------------------------------------------------------------------- Package : thunderbird CVE ID : CVE-2020-6819 CVE-2020-6820 CVE-2020-6821 CVE-2020-6822 CVE-2020-6825 Multiple security issues have been found in Thunderbird which could result in denial of service or potentially the execution of arbitrary code. For the oldstable distribution (stretch), these problems have been fixed in version 1:68.7.0-1~deb9u1. For the stable distribution (buster), these problems have been fixed in version 1:68.7.0-1~deb10u1. We recommend that you upgrade your thunderbird packages. For the detailed security status of thunderbird please refer to its security tracker page at: https://security-tracker.debian.org/tracker/thunderbird Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org - -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl6UwKQACgkQEMKTtsN8 TjYQpBAAsP95zkuaDBpomfJyzMU8ffUlDNSbmwg1bdccwjR4JSCpVqZB5nDRy2WD MzfuobwyQCzh/tPV8iFjbV0T78cR4QkokkwCwpSFcjoM79yPQTvgQBmDruuY78DQ v48vONAEzX5p8sJEHWLOHQGNrmiNfcndRlXiQcuPnN2Nz5wzQbvoD7MlIPs7t5Hl 5D7L242arir79GUmW84wHT9ixaEF72TTupNAJOdz7J3AGWP0vBSF1sv6U9bJ9mWq BbP1/JzNK665qyOIfsb4e1Qguk1Llpzx9FVE7g5sEraRajWjii0nOqVPLFlM3OIn 8ZU33b73n+3mkg4Iwq17Fhq4naqL2SiLM9JhPGIC0da7o6iRO/LHwXYgaIQzd4AP RrAfNLBgpgAnNtA394iMSeEYI3rC1bXoFBi9g1kXQXsA1AqFFuMiZpHnRlV0eUtv S6LpnZyu66JLDekbmkWAX2ckH5em96vdgOWJfG01n1dflQpWlqYWz8c4k2QEnpO5 GUlQ8jsBXY19wA5BIvC0RPGgCrwPBACDnQvisxcTOhZ9HOwb6HbvmMAway0K7d3t fk27M6oKDNrQ4/YyE9PcKuYMm0uFNHc89okUgrbCsz7SHiXBBGbTZuhd6dmUbOmw vBiYt0GM9dWY7ovEOYfF49QYhZ6RUMc0hhuLGHLgckTUNH/RgtU= =Zl8a - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXpU5amaOgq3Tt24GAQh9dQ//VSilGkQcLMugz1jYGy2aT2C4rpEAjUyM G+Av7ucSzrMpdSVqJe/ktPZTRT+YjSMEV7Z8KPu6GBzahrZV7vGaA11biI7p4RRo d4UutqsTu3MSdlWwJn5W6HObSIPwa1xZZufIfZHjw1eT1u6t35hLPKiV5P3SxL/N qtK5TaTNUlVxNsejj0ZDfs2Ri7wdzOQf8ffkv2ZL5JonYMP5ZrfbyEafSppZQd6C cpjwmEsaHO7Pf4XacLkuXP8JhqshNNC3ABujn8erMCb+yX/MsPpexQujsZT/DgBJ yNsGqtPDwxrJBS/vfDEYvvhGZtXM0C0DNWIJA2DRiP3dWq03xytKItitUYCly3VA SP2LZXsZS5aV2/xYRSacMlXWP1u7OtkLEcbpYdprDLgz1UlAtIPF6KRrcz3LUayw x38NdqoRkW43DXAN2IcZhTCN+t7FoGB5KCvpBD9DfVVPESqOs/auEm5QXtl08/27 waiBihNcswZbzeVr7vk8j/YYygzPTxLrHoXGMkxuBxecx1YuioKyF6Sobq8IXXRA B1O0SMxmw9fE6WlMeDoPXzys1EqlTnEwAiAvRDLC86V/iRM2QoIru5vnMXNXKVBt qbrTQ63+fLc+LTgcA/RzeGmjoxZ/mlKwJaWXgzGo4E/e0go7RD1n2v5tmt9/ow+E ESOJ1uDNkWk= =te3f -----END PGP SIGNATURE-----