Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 765088 (MFSA-2021-02) - <mail-client/thunderbird{,-bin}-78.6.1: SCTP use-after-free (CVE-2020-16044)
Summary: <mail-client/thunderbird{,-bin}-78.6.1: SCTP use-after-free (CVE-2020-16044)
Status: RESOLVED FIXED
Alias: MFSA-2021-02
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2 [glsa+]
Keywords:
Depends on:
Blocks: CVE-2020-16044
  Show dependency tree
 
Reported: 2021-01-12 12:37 UTC by Sam James
Modified: 2021-01-22 16:14 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-01-12 12:37:41 UTC
See tracker. Please bump to 78.6.1.
Comment 1 Larry the Git Cow gentoo-dev 2021-01-13 13:18:14 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6b8ab755e2f020b1628ed23c20d1fd02fa42b97c

commit 6b8ab755e2f020b1628ed23c20d1fd02fa42b97c
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2021-01-13 13:16:56 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-01-13 13:17:48 +0000

    mail-client/thunderbird-bin: (security) bump to 78.6.1
    
    Bug: https://bugs.gentoo.org/765088
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird-bin/Manifest               |  66 ++++
 .../thunderbird-bin/thunderbird-bin-78.6.1.ebuild  | 378 +++++++++++++++++++++
 2 files changed, 444 insertions(+)
Comment 2 Larry the Git Cow gentoo-dev 2021-01-13 15:36:04 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=565073d398e3a43df1a7c211f0957123d16711f4

commit 565073d398e3a43df1a7c211f0957123d16711f4
Author:     xor <davidhughes205@gmail.com>
AuthorDate: 2021-01-13 02:40:28 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-01-13 15:35:56 +0000

    mail-client/thunderbird: bump to 78.6.1 for CVE-2020-16044
    
    Bug: https://bugs.gentoo.org/765088
    Signed-off-by: Dave Hughes <davidhughes205@gmail.com>
    Closes: https://github.com/gentoo/gentoo/pull/19047
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird/Manifest                  |   65 ++
 mail-client/thunderbird/thunderbird-78.6.1.ebuild | 1053 +++++++++++++++++++++
 2 files changed, 1118 insertions(+)
Comment 3 Larry the Git Cow gentoo-dev 2021-01-14 06:28:23 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f3eb9e64926f28b629dbcb80e2107701e421fa0f

commit f3eb9e64926f28b629dbcb80e2107701e421fa0f
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2021-01-14 06:27:38 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-01-14 06:27:38 +0000

    mail-client/thunderbird: stabilize 78.6.1 on amd64
    
    Bug: https://bugs.gentoo.org/765088
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird/thunderbird-78.6.1.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=047e5919e67f937c8655dd862623da808ac3fd5c

commit 047e5919e67f937c8655dd862623da808ac3fd5c
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2021-01-14 06:27:10 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-01-14 06:27:10 +0000

    mail-client/thunderbird: stabilize 78.6.1 on x86
    
    Bug: https://bugs.gentoo.org/765088
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird/thunderbird-78.6.1.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-01-14 18:31:17 UTC
Please cleanup.
Comment 5 Joonas Niilola gentoo-dev 2021-01-14 18:39:38 UTC
Sure sure :) will wait a day or two for any possible issues with the newest ebuilds, to allow easy rollback should it be needed. KEYWORDS should match so by default no one should install those anymore.
Comment 6 Larry the Git Cow gentoo-dev 2021-01-15 17:31:09 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6877183cadf29134f02f2e88d82a121ceebea036

commit 6877183cadf29134f02f2e88d82a121ceebea036
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2021-01-15 17:21:32 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-01-15 17:21:32 +0000

    mail-client/thunderbird-bin: security cleanup
    
    Bug: https://bugs.gentoo.org/765088
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird-bin/Manifest               |  66 ----
 .../thunderbird-bin/thunderbird-bin-78.6.0.ebuild  | 378 ---------------------
 2 files changed, 444 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c0f7c58030aa48b475dc0fcea41a9f6976854a2e

commit c0f7c58030aa48b475dc0fcea41a9f6976854a2e
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2021-01-15 17:21:04 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-01-15 17:21:04 +0000

    mail-client/thunderbird: security cleanup
    
    Bug: https://bugs.gentoo.org/765088
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird/Manifest                  |   65 --
 mail-client/thunderbird/thunderbird-78.6.0.ebuild | 1053 ---------------------
 2 files changed, 1118 deletions(-)
Comment 7 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-01-15 18:27:27 UTC
Thanks!
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2021-01-22 16:14:11 UTC
This issue was resolved and addressed in
 GLSA 202101-14 at https://security.gentoo.org/glsa/202101-14
by GLSA coordinator Aaron Bauman (b-man).