MGASA-2017-0432

Source
https://advisories.mageia.org/MGASA-2017-0432.html
Import Source
https://advisories.mageia.org/MGASA-2017-0432.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0432
Related
Published
2017-11-29T18:52:42Z
Modified
2017-11-29T18:23:32Z
Summary
Updated thunderbird packages fix security vulnerabilities & bugs
Details

The updated packages fix several bugs and some security issues:

Use-after-free of PressShell while restyling layout. (CVE-2017-7828)

Cross-origin URL information leak through Resource Timing API. (CVE-2017-7830)

Memory safety bugs fixed in Firefox 57, Firefox ESR 52.5, and Thunderbird 52.5. (CVE-2017-7826)

References
Credits

Affected packages

Mageia:5 / thunderbird

Package

Name
thunderbird
Purl
pkg:rpm/mageia/thunderbird?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
52.5.0-1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / thunderbird-l10n

Package

Name
thunderbird-l10n
Purl
pkg:rpm/mageia/thunderbird-l10n?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
52.5.0-1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / thunderbird

Package

Name
thunderbird
Purl
pkg:rpm/mageia/thunderbird?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
52.5.0-1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / thunderbird-l10n

Package

Name
thunderbird-l10n
Purl
pkg:rpm/mageia/thunderbird-l10n?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
52.5.0-1.mga6

Ecosystem specific

{
    "section": "core"
}