Oval Definition:oval:com.redhat.rhsa:def:20171201
Revision Date:2017-05-08Version:639
Title:RHSA-2017:1201: thunderbird security update (Important)
Description:Mozilla Thunderbird is a standalone mail and newsgroup client.

This update upgrades Thunderbird to version 52.1.0.

Security Fix(es):

  • Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2017-5429, CVE-2017-5433, CVE-2017-5435, CVE-2017-5436, CVE-2017-5459, CVE-2017-5466, CVE-2017-5432, CVE-2017-5434, CVE-2017-5438, CVE-2017-5439, CVE-2017-5440, CVE-2017-5441, CVE-2017-5442, CVE-2017-5443, CVE-2017-5444, CVE-2017-5446, CVE-2017-5447, CVE-2017-5454, CVE-2017-5460, CVE-2017-5464, CVE-2017-5465, CVE-2017-5469, CVE-2016-10195, CVE-2016-10196, CVE-2017-5445, CVE-2017-5449, CVE-2017-5451, CVE-2017-5467, CVE-2016-10197)

    Red Hat would like to thank the Mozilla project for reporting these issues. Upstream acknowledges Petr Cerny, Nils, Ivan Fratric (Google Project Zero), Takeshi Terada, Heather Miller (Google Skia team), Chun Han Hsiao, Chamal De Silva, Nicolas Grégoire, Holger Fuhrmannek, Atte Kettunen, Haik Aftandilian, and Jordi Chancel as the original reporters.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-10195
    CVE-2016-10196
    CVE-2016-10197
    CVE-2017-5429
    CVE-2017-5432
    CVE-2017-5433
    CVE-2017-5434
    CVE-2017-5435
    CVE-2017-5436
    CVE-2017-5438
    CVE-2017-5439
    CVE-2017-5440
    CVE-2017-5441
    CVE-2017-5442
    CVE-2017-5443
    CVE-2017-5444
    CVE-2017-5445
    CVE-2017-5446
    CVE-2017-5447
    CVE-2017-5449
    CVE-2017-5451
    CVE-2017-5454
    CVE-2017-5459
    CVE-2017-5460
    CVE-2017-5464
    CVE-2017-5465
    CVE-2017-5466
    CVE-2017-5467
    CVE-2017-5469
    RHSA-2017:1201
    RHSA-2017:1201-00
    RHSA-2017:1201-01
    Platform(s):Red Hat Enterprise Linux 6
    Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND thunderbird is earlier than 0:52.1.0-1.el7_3
  • AND thunderbird is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND thunderbird is earlier than 0:52.1.0-1.el6_9
  • AND thunderbird is signed with Red Hat redhatrelease2 key
  • BACK