[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2021-1586 --- thunderbird

ID: oval:org.secpod.oval:def:1700530Date: (C)2021-01-15   (M)2024-02-19
Class: PATCHFamily: unix




When drawing a transparent image on top of an unknown cross-origin image, the Skia library `drawImage` function took a variable amount of time depending on the content of the underlying image. This resulted in potential cross-origin information exposure of image content through timing side-channel attacks. The Mozilla Foundation Security Advisory describes this flaw as:When a BigInt was right-shifted the backing store was not properly cleared, allowing uninitialized memory to be read. A parsing and event loading mismatch in Firefox"s SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox CVE-2020-26951

Platform:
Amazon Linux 2
Product:
thunderbird
Reference:
ALAS2-2021-1586
CVE-2020-16012
CVE-2020-16042
CVE-2020-26951
CVE-2020-26953
CVE-2020-26956
CVE-2020-26958
CVE-2020-26959
CVE-2020-26960
CVE-2020-26961
CVE-2020-26965
CVE-2020-26968
CVE-2020-26971
CVE-2020-26973
CVE-2020-26974
CVE-2020-26978
CVE-2020-35111
CVE-2020-35113
CVE    17
CVE-2020-26951
CVE-2020-26973
CVE-2020-26961
CVE-2020-26960
...

© SecPod Technologies