PT-2019-3441 · Mozilla+5 · Thunderbird+5

Luis Merino

·

Published

2019-06-13

·

Updated

2024-06-15

·

CVE-2019-11706

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 60.7.1
Description A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone get vtimezone properties when processing certain email messages, resulting in a crash. The vulnerability is related to a lack of type checking of the passed object, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For Thunderbird versions prior to 60.7.1, update to version 60.7.1 or later to resolve the issue. As a temporary workaround, consider avoiding the processing of suspicious email messages that may trigger the type confusion in icaltimezone get vtimezone properties.

Exploit

Fix

Type Confusion

Incorrect Type Conversion or Cast

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2075
ALT-PU-2019-2078
BDU:2019-03612
CESA-2019_1623
CESA-2019_1624
CESA-2019_1626
CVE-2019-11706
DLA-1820-1
DSA-4464-1
MGASA-2019-0193
OPENSUSE-SU-2019:1583-1
OPENSUSE-SU-2019:1606-1
OPENSUSE-SU-2019:1664-1
OPENSUSE-SU-2019_1577-1
OPENSUSE-SU-2019_1583-1
OPENSUSE-SU-2019_1606-1
OPENSUSE-SU-2024:10601-1
RHSA-2019:1623
RHSA-2019:1624
RHSA-2019:1626
RHSA-2019_1623
RHSA-2019_1624
RHSA-2019_1626
SUSE-SU-2019:1495-1
SUSE-SU-2019:1683-1
USN-4028-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Thunderbird
Ubuntu