Releases Security Update for Thunderbird 60.6.1 (March 25, 2019)

Ref# Mozilla | Date: Apr 24th 2019

Description

The Microsoft Foundation released several security vulnerability fixes for the thunderbird 60.6.1. It is recommended to take the necessary precautions by ensuring products are always updated to avoid an attacker from exploiting one of these vulnerabilities by taking control of an affected system.

The Thunderbird 60.6.1 update includes, 2 critical vulnerability fixes.

Critical

  • CVE-2019-9810: IonMonkey MArraySlice has incorrect alias information
  • CVE-2019-9813: Ionmonkey type confusion with __proto__ mutations

The Guyana National CIRT recommends that users and administration review these updates and apply them where necessary.

Reference

  • Mozilla Foundation Security Advisory 2019-10 (US-Cert)

https://www.mozilla.org/en-US/security/advisories/mfsa2019-12/#CVE-2019-9813