Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.844495
Categoría:Ubuntu Local Security Checks
Título:Ubuntu: Security Advisory for thunderbird (USN-4421-1)
Resumen:The remote host is missing an update for the 'thunderbird'; package(s) announced via the USN-4421-1 advisory.
Descripción:Summary:
The remote host is missing an update for the 'thunderbird'
package(s) announced via the USN-4421-1 advisory.

Vulnerability Insight:
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, or execute arbitrary code. (CVE-2020-12405,
CVE-2020-12406, CVE-2020-12410, CVE-2020-12417, CVE-2020-12418,
CVE-2020-12419, CVE-2020-12420)

It was discovered that Thunderbird would continue an unencrypted
connection when configured to use STARTTLS for IMAP if the server
responded with PREAUTH. A remote attacker could potentially exploit
this to perform a person-in-the-middle attack in order to obtain
sensitive information. (CVE-2020-12398)

It was discovered that NSS showed timing differences when performing DSA
signatures. An attacker could potentially exploit this to obtain private
keys using a timing attack. (CVE-2020-12399)

It was discovered that when performing add-on updates, certificate chains
not terminating with built-in roots were silently rejected. This could
result in add-ons becoming outdated. (CVE-2020-12421)

Affected Software/OS:
'thunderbird' package(s) on Ubuntu 20.04 LTS, Ubuntu 19.10, Ubuntu 18.04 LTS, Ubuntu 16.04 LTS.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2020-12405
Common Vulnerability Exposure (CVE) ID: CVE-2020-12406
Common Vulnerability Exposure (CVE) ID: CVE-2020-12410
Common Vulnerability Exposure (CVE) ID: CVE-2020-12417
Common Vulnerability Exposure (CVE) ID: CVE-2020-12418
Common Vulnerability Exposure (CVE) ID: CVE-2020-12419
Common Vulnerability Exposure (CVE) ID: CVE-2020-12420
Common Vulnerability Exposure (CVE) ID: CVE-2020-12398
Common Vulnerability Exposure (CVE) ID: CVE-2020-12399
Common Vulnerability Exposure (CVE) ID: CVE-2020-12421
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.