From deba8115d2c2af26df42966b91ef04ff4dd79cde Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Thu, 14 May 2020 11:09:11 +0100 Subject: gentoo resync : 14.05.2020 --- metadata/glsa/glsa-202005-03.xml | 72 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 72 insertions(+) create mode 100644 metadata/glsa/glsa-202005-03.xml (limited to 'metadata/glsa/glsa-202005-03.xml') diff --git a/metadata/glsa/glsa-202005-03.xml b/metadata/glsa/glsa-202005-03.xml new file mode 100644 index 000000000000..0311ac6901f8 --- /dev/null +++ b/metadata/glsa/glsa-202005-03.xml @@ -0,0 +1,72 @@ + + + + Mozilla Thunderbird: Multiple vulnerabilities + Multiple vulnerabilities have been found in Mozilla Thunderbird, + the worst of which could result in the arbitrary execution of code. + + thunderbird + 2020-05-12 + 2020-05-12 + 721324 + remote + + + 68.8.0 + 68.8.0 + + + 68.8.0 + 68.8.0 + + + +

Mozilla Thunderbird is a popular open-source email client from the + Mozilla project. +

+
+ +

Multiple vulnerabilities have been discovered in Mozilla Thunderbird. + Please review the CVE identifiers referenced below for details. +

+
+ +

A remote attacker may be able to execute arbitrary code, cause a Denial + of Service condition or spoof sender email address. +

+
+ +

There is no known workaround at this time.

+
+ +

All Mozilla Thunderbird users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=mail-client/thunderbird-68.8.0" + + +

All Mozilla Thunderbird binary users should upgrade to the latest + version: +

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=mail-client/thunderbird-bin-68.8.0" + + +
+ + CVE-2020-12387 + CVE-2020-12392 + CVE-2020-12395 + CVE-2020-12397 + CVE-2020-6831 + + MFSA-2020-18 + + + sam_c + sam_c +
-- cgit v1.2.3