Number: AV17-153
Date: 11 October 2017
Purpose
The purpose of this advisory is to bring attention to a security update addressing multiple vulnerabilities in Thunderbird.
Assessment
Mozilla released security updates to address 9 vulnerabilities in Thunderbird.
The severity of these issues ranges from moderate to critical.
Versions affected:
Thunderbird versions prior to 52.4
CVE References: CVE-2017-7793, CVE-2017-7818, CVE-2017-7819, CVE-2017-7824, CVE-2017-7805, CVE-2017-7814, CVE-2017-7825, CVE-2017-7823, CVE-2017-7810
Suggested Action
CCIRC recommends that owner/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.
References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-23/