QID 198643

Date Published: 2022-01-24

QID 198643: Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5246-1)

Javascript was unexpectedly enabled in thecomposition area.
Thunderbird's openpgp integration only consideredthe inner signed message when checking signature validity in a messagethat contains an additional outer mime layer.

Multiple security issues were discovered in thunderbird.
If a user weretricked into opening a specially crafted website in a browsing context, anattacker could potentially exploit these to cause a denial of service,obtain sensitive information, conduct spoofing attacks, bypass securityrestrictions, or execute arbitrary code.
An attacker could potentially exploit this incombination with another vulnerability, with unspecified impacts.
(cve-2021-43528)a buffer overflow was discovered in the matrix chat library bundled withthunderbird.
An attacker could potentially exploit this to cause a denialof service, or execute arbitrary code.
An attacker couldpotentially exploit this to trick the user into thinking that a messagehas a valid signature.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5246-1 for updates and patch information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5246-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5246-1