SB2018103040 - Red Hat update for thunderbird
Published: October 30, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 secuirty vulnerabilities.
1) Security restrictions bypass (CVE-ID: CVE-2017-16541)
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to content can be loaded from the mounted file system directly using a file: URI. A remote unauthenticated attacker can use the automount feature with autofs to create a mount point on the local file system and bypass browser proxy settings.
2) Memory corruption (CVE-ID: CVE-2018-12376)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error when handling malicious input. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
3) Use-after-free (CVE-ID: CVE-2018-12377)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to use-after-free error when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
4) Use-after-free (CVE-ID: CVE-2018-12378)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to use-after-free error when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
5) Out-of-bounds write (CVE-ID: CVE-2018-12379)
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists due to out-of-bounds write when the Mozilla Updater opens a MAR format file which contains a very long item filename. A local attacker can run the Mozilla Updater on the local system with the malicious MAR file, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
6) Information disclosure (CVE-ID: CVE-2018-12383)
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to the older stored password file was not deleted when the data was copied to a new format starting. A remote unauthenticated attacker can access stored password data.
7) Input validation error (CVE-ID: CVE-2018-12385)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists within the TransportSecurityInfo function due to insufficient validation of data stored in the local cache in the user profile directory. A remote attacker with ability to write data into local cache (e.g. with combination of another vulnerability) can execute arbitrary code on the target system.
Remediation
Install update from vendor's website.