libical: Heap buffer over read in icalparser.c parser_get_next_char
Published Jul 23, 2019
9.8
CRITICALCVSS 3.1
EPSS 10.53%
Description
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.
Affected products
-
Affected
- ≥ unspecified, < 60.7.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Mozilla | Thunderbird | unknown | Affected
|
- < 60.7.1
No data.
Red Hat Enterprise Linux 6
thunderbird-0:60.7.2-2.el6_10
Fixed · RHSA-2019:1624
Red Hat Enterprise Linux 7
thunderbird-0:60.7.2-2.el7_6
Fixed · RHSA-2019:1626
Red Hat Enterprise Linux 8
thunderbird-0:60.7.2-2.el8_0
Fixed · RHSA-2019:1623
Red Hat Enterprise Linux 6
libical
Out of support scope
Red Hat Enterprise Linux 7
libical
Not affected
Red Hat Enterprise Linux 8
libical
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | thunderbird-0:60.7.2-2.el6_10 | Fixed | RHSA-2019:1624 |
| Red Hat Enterprise Linux 7 | thunderbird-0:60.7.2-2.el7_6 | Fixed | RHSA-2019:1626 |
| Red Hat Enterprise Linux 8 | thunderbird-0:60.7.2-2.el8_0 | Fixed | RHSA-2019:1623 |
| Red Hat Enterprise Linux 6 | libical | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libical | Not affected | n/a |
| Red Hat Enterprise Linux 8 | libical | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Thunderbird can be configured to use icaljs instead of libical by setting `calendar.icaljs = true` in preferences, mitigating this vulnerability.
References (9)
- https://access.redhat.com/security/cve/CVE-2019-11703 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1553820 x_refsource_MISCExploitIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1720001 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3373 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-11703
- https://security.gentoo.org/glsa/201908-20 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11703
- https://www.mozilla.org/en-US/security/advisories/mfsa2019-17/
- https://www.mozilla.org/security/advisories/mfsa2019-17/ x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-11703 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1553820 | x_refsource_MISCExploitIssue TrackingVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1720001 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3373 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-11703 | ||
| https://security.gentoo.org/glsa/201908-20 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-11703 | ||
| https://www.mozilla.org/en-US/security/advisories/mfsa2019-17/ | ||
| https://www.mozilla.org/security/advisories/mfsa2019-17/ | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data