PT-2019-3441 · Mozilla+5 · Thunderbird+5

Luis Merino

·

Publicado

2019-06-13

·

Atualizado

2024-06-15

·

CVE-2019-11706

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 60.7.1
Description A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone get vtimezone properties when processing certain email messages, resulting in a crash. The vulnerability is related to a lack of type checking of the passed object, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For Thunderbird versions prior to 60.7.1, update to version 60.7.1 or later to resolve the issue. As a temporary workaround, consider avoiding the processing of suspicious email messages that may trigger the type confusion in icaltimezone get vtimezone properties.

Exploit

Correção

Type Confusion

Incorrect Type Conversion or Cast

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2075
ALT-PU-2019-2078
BDU:2019-03612
CESA-2019_1623
CESA-2019_1624
CESA-2019_1626
CVE-2019-11706
DLA-1820-1
DSA-4464-1
MGASA-2019-0193
OPENSUSE-SU-2019:1583-1
OPENSUSE-SU-2019:1606-1
OPENSUSE-SU-2019:1664-1
OPENSUSE-SU-2019_1577-1
OPENSUSE-SU-2019_1583-1
OPENSUSE-SU-2019_1606-1
OPENSUSE-SU-2024:10601-1
RHSA-2019:1623
RHSA-2019:1624
RHSA-2019:1626
RHSA-2019_1623
RHSA-2019_1624
RHSA-2019_1626
SUSE-SU-2019:1495-1
SUSE-SU-2019:1683-1
USN-4028-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Thunderbird
Ubuntu