The Mozilla Foundation and Google released “high” rated security updates for Thunderbird and Chrome, respectively.
The high-rated Thunderbird vulnerabilities patched in version 60.7.1 are CVE-2019-11703 and CVE-2017-11704 concern a heep buffer overflow in icalparser.c and another in Icalfvalue.c. The former flaw can cause a flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char, while the second has the same problem but in icalmemory_strdup_and_dequote. In each case processing certain email messages can in a potentially exploitable crash.
The low-rated CVE-2019-11705 is for a type confusion in icalproperty.c due to Thunderbird’s implementation of iCal can cause a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash.
Please register to continue.
Already registered? Log in.
Once you register, you'll receive:
The context and insight you need to stay abreast of the most important developments in cybersecurity. CISO and practitioner perspectives; strategy and tactics; solutions and innovation; policy and regulation.
Unlimited access to nearly 20 years of SC Media industry analysis and news-you-can-use.
SC Media’s essential morning briefing for cybersecurity professionals.
One-click access to our extensive program of virtual events, with convenient calendar reminders and ability to earn CISSP credits.