thunderbird-38.7.0-1.AXS4

エラータID: AXSA:2016-141:03

Release date: 
Thursday, March 17, 2016 - 02:26
Subject: 
thunderbird-38.7.0-1.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Mozilla Thunderbird is a standalone mail and newsgroup client.

Security issues fixed with this release:

CVE-2016-1952
Multiple unspecified vulnerabilities in the browser engine in Mozilla
Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote
attackers to cause a denial of service (memory corruption and
application crash) or possibly execute arbitrary code via unknown
vectors.
CVE-2016-1954
The nsCSPContext::SendReports function in
dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and
Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP
report-uri for a Content Security Policy (CSP) violation report, which
allows remote attackers to cause a denial of service (data overwrite)
or possibly gain privileges by specifying a URL of a local file.
CVE-2016-1957
Memory leak in libstagefright in Mozilla Firefox before 45.0 and
Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial
of service (memory consumption) via an MPEG-4 file that triggers a
delete operation on an array.
CVE-2016-1960
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string
parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7
allows remote attackers to execute arbitrary code or cause a denial of
service (use-after-free) by leveraging mishandling of end tags, as
demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.
CVE-2016-1961
Use-after-free vulnerability in the nsHTMLDocument::SetBody function
in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and
Firefox ESR 38.x before 38.7 allows remote attackers to execute
arbitrary code by leveraging mishandling of a root element, aka
ZDI-CAN-3574.
CVE-2016-1964
Use-after-free vulnerability in the AtomicBaseIncDec function in
Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows
remote attackers to execute arbitrary code or cause a denial of
service (heap memory corruption) by leveraging mishandling of XML
transformations.
CVE-2016-1966
The nsNPObjWrapper::GetNewOrUsed function in
dom/plugins/base/nsJSNPRuntime.cpp in Mozilla Firefox before 45.0 and
Firefox ESR 38.x before 38.7 allows remote attackers to execute
arbitrary code or cause a denial of service (invalid pointer
dereference and memory corruption) via a crafted NPAPI plugin.
CVE-2016-1974
The nsScannerString::AppendUnicodeTo fynction in Mozilla Firefox
before 45.0 and Firefox ESR 38.x before 38.7 does not verify that
memory allocation succeeds, which allows remote attackers to execute
arbitrary code or cause a denial of service (out-of-bounds read) via
crafted Unicode data in an HTML, XML, or SVG document.
CVE-2016-1977
The Machine::Code::decoder::analysis::set_ref function in Graphite 2
before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR
38.x before 38.7, allows remote attackers to execute arbitrary code or
cause a denial of service (stack memory corruption) via a crafted
Graphite smart font.
CVE-2016-2790
The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before
1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x
before 38.7, does not initialize memory for an unspecified data
structure, which allows remote attackers to cause a denial of service
or possibly have unknown other impact via a crafted Graphite smart
font.
CVE-2016-2791
The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6,
as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before
38.7, allows remote attackers to cause a denial of service (buffer
over-read) or possibly have unspecified other impact via a crafted
Graphite smart font.
CVE-2016-2792
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before
1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x
before 38.7, allows remote attackers to cause a denial of service
(buffer over-read) or possibly have unspecified other impact via a
crafted Graphite smart font, a different vulnerability than
CVE-2016-2800.
CVE-2016-2793
CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox
before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers
to cause a denial of service (buffer over-read) or possibly have
unspecified other impact via a crafted Graphite smart font.
CVE-2016-2794
The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in
Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and
Firefox ESR 38.x before 38.7, allows remote attackers to cause a
denial of service (buffer over-read) or possibly have unspecified
other impact via a crafted Graphite smart font.
CVE-2016-2795
The graphite2::FileFace::get_table_fn function in Graphite 2 before
1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x
before 38.7, does not initialize memory for an unspecified data
structure, which allows remote attackers to cause a denial of service
or possibly have unknown other impact via a crafted Graphite smart
font.
CVE-2016-2796
Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code
function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before
45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to
cause a denial of service or possibly have unspecified other impact
via a crafted Graphite smart font.
CVE-2016-2797
The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2
before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR
38.x before 38.7, allows remote attackers to cause a denial of service
(buffer over-read) or possibly have unspecified other impact via a
crafted Graphite smart font, a different vulnerability than
CVE-2016-2801.
CVE-2016-2798
The graphite2::GlyphCache::Loader::Loader function in Graphite 2
before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR
38.x before 38.7, allows remote attackers to cause a denial of service
(buffer over-read) or possibly have unspecified other impact via a
crafted Graphite smart font.
CVE-2016-2799
Heap-based buffer overflow in the graphite2::Slot::setAttr function in
Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and
Firefox ESR 38.x before 38.7, allows remote attackers to cause a
denial of service or possibly have unspecified other impact via a
crafted Graphite smart font.
CVE-2016-2800
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before
1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x
before 38.7, allows remote attackers to cause a denial of service
(buffer over-read) or possibly have unspecified other impact via a
crafted Graphite smart font, a different vulnerability than
CVE-2016-2792.
CVE-2016-2801
The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp
in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and
Firefox ESR 38.x before 38.7, allows remote attackers to cause a
denial of service (buffer over-read) or possibly have unspecified
other impact via a crafted Graphite smart font, a different
vulnerability than CVE-2016-2797.
CVE-2016-2802
The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in
Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and
Firefox ESR 38.x before 38.7, allows remote attackers to cause a
denial of service (buffer over-read) or possibly have unspecified
other impact via a crafted Graphite smart font.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. thunderbird-38.7.0-1.AXS4.src.rpm
    MD5: a7f73ec61411a234a0c39724e69b63bf
    SHA-256: 5e5f45a8396b0cbcace3a7a986e8373ba95f40d061580dee282ca42450c81498
    Size: 357.16 MB

Asianux Server 4 for x86
  1. thunderbird-38.7.0-1.AXS4.i686.rpm
    MD5: 9f4a77950d344df7f5158c2c2543c5b2
    SHA-256: 7311827263827dd3f776c3a6475c598d351e8540fac5630b71c1266e3069debd
    Size: 56.95 MB

Asianux Server 4 for x86_64
  1. thunderbird-38.7.0-1.AXS4.x86_64.rpm
    MD5: b11d2f19f346df4fb468027706d6a060
    SHA-256: 0dd2b01a17138bca679f067f80023e0003b60376d64b569500d5584d78bfef03
    Size: 56.20 MB