SB2023041732 - Red Hat Enterprise Linux 7 update for thunderbird 



SB2023041732 - Red Hat Enterprise Linux 7 update for thunderbird

Published: April 17, 2023

Security Bulletin ID SB2023041732
Severity
High
Patch available
YES
Number of vulnerabilities 11
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 27% Medium 55% Low 18%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 11 secuirty vulnerabilities.


1) Security features bypass (CVE-ID: CVE-2023-0547)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an error when processing revocation status of S/mime recipient certificates. OCSP revocation status of recipient certificates is not checked when sending S/Mime encrypted email, as a result revoked certificates are accepted.


2) Buffer overflow (CVE-ID: CVE-2023-1945)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the Safe Browsing API. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


3) Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CVE-ID: CVE-2023-28427)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a prototype pollution issue in Matrix SDK. A remote attacker can pass specially crafted input with events containing special strings in key locations and perform a denial of service (DoS) attack.


4) Input validation error (CVE-ID: CVE-2023-29479)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input within the Ribose RNP library when parsing PKESK/SKESK packets. A remote attacker can send specially crafted OpenPGP messages to the application and perform a denial of service (DoS) attack.


5) Spoofing attack (CVE-ID: CVE-2023-29533)

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to incorrect processing of user-supplied data. A remote attacker can hide the fullscreen notification by using a combination of window.open, fullscreen requests, window.name assignments, and setInterval calls.


6) Buffer overflow (CVE-ID: CVE-2023-29535)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error during Garbage Collector compaction. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


7) Release of invalid pointer or reference (CVE-ID: CVE-2023-29536)

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to an invalid free operation from JavaScript code. A remote attacker can trick the victim to visit a specially crafted web page, trigger memory corruption and execute arbitrary code.


8) Security features bypass (CVE-ID: CVE-2023-29539)

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper handling of filename directive in the Content-Disposition header, which leads to filename truncation if it contains a NULL character. A remote attacker can abuse such behavior and trick the victim into downloading a malicious file.


9) Security features bypass (CVE-ID: CVE-2023-29541)

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper handling of filenames ending with .desktop. A remote attacker can trick the victim into downloading a malicious file and execute it on the system.

The vulnerability affects Firefox on Linux only.


10) Processor optimization removal or modification of security-critical code (CVE-ID: CVE-2023-29548)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to usage of a wrong lowering instruction in the ARM64 Ion compiler. A remote attacker can gain access to sensitive information.


11) Buffer overflow (CVE-ID: CVE-2023-29550)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when parsing HTML content. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install update from vendor's website.