thunderbird-60.3.0-1.AXS4
エラータID: AXSA:2018-3431:07
リリース日:
2018/12/10 Monday - 05:13
題名:
thunderbird-60.3.0-1.AXS4
影響のあるチャネル:
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
現在のところ以下の CVE は公開されておりません。
CVE の情報が公開され次第情報をアップデートいたします。
- CVE-2018-12389
- CVE-2018-12390
- CVE-2018-12392
- CVE-2018-12393
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2018-12389
Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.3 and Thunderbird < 60.3.
Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.3 and Thunderbird < 60.3.
CVE-2018-12390
Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
CVE-2018-12392
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
CVE-2018-12393
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit builds are not vulnerable to this issue.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit builds are not vulnerable to this issue.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
追加情報:
N/A
ダウンロード:
SRPMS
- thunderbird-60.3.0-1.AXS4.src.rpm
MD5: 8852ff71988e2b947bcc2c866d0d710d
SHA-256: c01aa676df8dd99d2bb1ac71d86228057dca5cc2bec398613befc87921fc4df7
Size: 421.68 MB
Asianux Server 4 for x86
- thunderbird-60.3.0-1.AXS4.i686.rpm
MD5: 662775c3f559951b67aa0710f9dc872d
SHA-256: 718b9f70366d95fc091e6b49a018d6bf1ee25bfe0327c9016a8ccf1b9feb0ecf
Size: 100.61 MB
Asianux Server 4 for x86_64
- thunderbird-60.3.0-1.AXS4.x86_64.rpm
MD5: 4a21ff0eb0bb632736a12915eca9398f
SHA-256: cc92ed139d079dfa902750d8f5de3da3cb7e24f5d99cde320252974e25543c3f
Size: 100.37 MB