From foxboron@archlinux.org Tue Jan 14 19:17:58 2020 From: Morten Linderud To: arch-security@lists.archlinux.org Subject: [ASA-202001-4] thunderbird: multiple issues Date: Tue, 14 Jan 2020 20:17:39 +0100 Message-ID: <20200114191739.c33nelsp6cfnldyr@anathema> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============4682619001867615757==" --===============4682619001867615757== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Arch Linux Security Advisory ASA-202001-4 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Severity: Critical Date : 2020-01-14 CVE-ID : CVE-2019-17016 CVE-2019-17017 CVE-2019-17022 CVE-2019-17024 CVE-2019-17026 Package : thunderbird Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1086 Summary =3D=3D=3D=3D=3D=3D=3D The package thunderbird before version 68.4.1-1 is vulnerable to multiple issues including arbitrary code execution and insufficient validation. Resolution =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Upgrade to 68.4.1-1. # pacman -Syu "thunderbird>=3D68.4.1-1" The problems have been fixed upstream in version 68.4.1. Workaround =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D None. Description =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D - CVE-2019-17016 (insufficient validation) A security issue has been found in Firefox before 72.0, and Thunderbird before 68.4.1. When pasting a