Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 765088 (MFSA-2021-02)

Summary: <mail-client/thunderbird{,-bin}-78.6.1: SCTP use-after-free (CVE-2020-16044)
Product: Gentoo Security Reporter: Sam James <sam>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: major CC: mozilla
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: A2 [glsa+]
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 765085    

Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-01-12 12:37:41 UTC
See tracker. Please bump to 78.6.1.
Comment 1 Larry the Git Cow gentoo-dev 2021-01-13 13:18:14 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6b8ab755e2f020b1628ed23c20d1fd02fa42b97c

commit 6b8ab755e2f020b1628ed23c20d1fd02fa42b97c
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2021-01-13 13:16:56 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-01-13 13:17:48 +0000

    mail-client/thunderbird-bin: (security) bump to 78.6.1
    
    Bug: https://bugs.gentoo.org/765088
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird-bin/Manifest               |  66 ++++
 .../thunderbird-bin/thunderbird-bin-78.6.1.ebuild  | 378 +++++++++++++++++++++
 2 files changed, 444 insertions(+)
Comment 2 Larry the Git Cow gentoo-dev 2021-01-13 15:36:04 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=565073d398e3a43df1a7c211f0957123d16711f4

commit 565073d398e3a43df1a7c211f0957123d16711f4
Author:     xor <davidhughes205@gmail.com>
AuthorDate: 2021-01-13 02:40:28 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-01-13 15:35:56 +0000

    mail-client/thunderbird: bump to 78.6.1 for CVE-2020-16044
    
    Bug: https://bugs.gentoo.org/765088
    Signed-off-by: Dave Hughes <davidhughes205@gmail.com>
    Closes: https://github.com/gentoo/gentoo/pull/19047
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird/Manifest                  |   65 ++
 mail-client/thunderbird/thunderbird-78.6.1.ebuild | 1053 +++++++++++++++++++++
 2 files changed, 1118 insertions(+)
Comment 3 Larry the Git Cow gentoo-dev 2021-01-14 06:28:23 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f3eb9e64926f28b629dbcb80e2107701e421fa0f

commit f3eb9e64926f28b629dbcb80e2107701e421fa0f
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2021-01-14 06:27:38 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-01-14 06:27:38 +0000

    mail-client/thunderbird: stabilize 78.6.1 on amd64
    
    Bug: https://bugs.gentoo.org/765088
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird/thunderbird-78.6.1.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=047e5919e67f937c8655dd862623da808ac3fd5c

commit 047e5919e67f937c8655dd862623da808ac3fd5c
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2021-01-14 06:27:10 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-01-14 06:27:10 +0000

    mail-client/thunderbird: stabilize 78.6.1 on x86
    
    Bug: https://bugs.gentoo.org/765088
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird/thunderbird-78.6.1.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-01-14 18:31:17 UTC
Please cleanup.
Comment 5 Joonas Niilola gentoo-dev 2021-01-14 18:39:38 UTC
Sure sure :) will wait a day or two for any possible issues with the newest ebuilds, to allow easy rollback should it be needed. KEYWORDS should match so by default no one should install those anymore.
Comment 6 Larry the Git Cow gentoo-dev 2021-01-15 17:31:09 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6877183cadf29134f02f2e88d82a121ceebea036

commit 6877183cadf29134f02f2e88d82a121ceebea036
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2021-01-15 17:21:32 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-01-15 17:21:32 +0000

    mail-client/thunderbird-bin: security cleanup
    
    Bug: https://bugs.gentoo.org/765088
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird-bin/Manifest               |  66 ----
 .../thunderbird-bin/thunderbird-bin-78.6.0.ebuild  | 378 ---------------------
 2 files changed, 444 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c0f7c58030aa48b475dc0fcea41a9f6976854a2e

commit c0f7c58030aa48b475dc0fcea41a9f6976854a2e
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2021-01-15 17:21:04 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2021-01-15 17:21:04 +0000

    mail-client/thunderbird: security cleanup
    
    Bug: https://bugs.gentoo.org/765088
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird/Manifest                  |   65 --
 mail-client/thunderbird/thunderbird-78.6.0.ebuild | 1053 ---------------------
 2 files changed, 1118 deletions(-)
Comment 7 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-01-15 18:27:27 UTC
Thanks!
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2021-01-22 16:14:11 UTC
This issue was resolved and addressed in
 GLSA 202101-14 at https://security.gentoo.org/glsa/202101-14
by GLSA coordinator Aaron Bauman (b-man).