Mozilla Fixes Code Execution Vulnerabilities in Thunderbird

Mozilla Releases Security Update for Thunderbird

Mozilla has released a security update for its email client, Thunderbird, addressing several vulnerabilities that could allow code execution on affected systems. The update, version 60.7.1, resolves a total of four vulnerabilities: three rated as high severity and one as low severity.

Details of the Vulnerabilities

  • CVE-2019-11703 – Buffer overflow in the icalparser.c function.
  • CVE-2019-11704 – Buffer overflow in the icalvalue.c function.
  • CVE-2019-11705 – Stack buffer overflow in the calrecur.c function.
  • CVE-2019-11706 – A less severe vulnerability tracked in the icalproperty.c function.

All versions of Thunderbird prior to 60.7.1 are affected by these security issues. Mozilla has stated that there have been no reports of these vulnerabilities being exploited in real-world attacks.

Recommendation

Users are strongly advised to update Thunderbird to version 60.7.1 or later to protect their systems from potential threats.

Leave a Reply