For eligibility requirements, please refer to the following link: Please note that this option is available only to eligible Staff and Faculty members who have been approved by an Authorized Departmental FASmail Contact/Administrator. While setup documentation for various Email applications are provided below, we recommend using the Outlook Web App to access your mailbox. The setup documents listed below are step-by-step instructions for configuring your email client to use the UBC Faculty and Staff email (FASmail) service. Please refer to the instructions provided for more details: Without this change, you may encounter difficulties searching for recipient names or accessing the Global Address List (GAL). Memory safety bugs fixed in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.Update Required for FASmail Users on Microsoft Outlook for Mac by May 29, 2023Įffective users who access their FASmail accounts using Microsoft Outlook for Mac must make a simple account settings update to ensure continued secure usage of our directory service.Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. #CVE-2023-6864: Memory safety bugs fixed in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6 Reporter Andrew McCreight, the Mozilla Fuzzing Team, Karl Tomlinson, Valentin Gosu, Randell Jesup, Yury Delendik Impact high Description The ShutdownObserver() was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. #CVE-2023-6863: Undefined behavior in ShutdownObserver() Reporter Ronald Crane Impact low Description This issue appears to manifest rarely during start-up. #CVE-2023-6862: Use-after-free in nsDNSService Reporter Randell Jesup Impact moderate DescriptionĪ use-after-free was identified in the nsDNSService::Init. The nsWindow::PickerOpen(void) method was susceptible to a heap buffer overflow when running in headless mode. #CVE-2023-6861: Heap buffer overflow affected nsWindow::PickerOpen(void) in headless mode Reporter Yangkang of 360 ATA Team Impact moderate Description This could be abused to escape the sandbox. The VideoBridge allowed any content process to use textures produced by remote decoders. #CVE-2023-6860: Potential sandbox escape due to VideoBridge lack of texture validation Reporter Andrew Osmond Impact moderate Description #CVE-2023-6859: Use-after-free in PR_GetIdentitiesLayer Reporter Irvan Kurniawan Impact moderate DescriptionĪ use-after-free condition affected TLS socket creation when under memory pressure. Thunderbird was susceptible to a heap buffer overflow in nsTextFragment due to insufficient OOM handling. #CVE-2023-6858: Heap buffer overflow in nsTextFragment Reporter Irvan Kurniawan Impact moderate Description This bug only affects Thunderbird on Unix-based operating systems (Android, Linux, MacOS). When resolving a symlink, a race may occur where the buffer passed to readlink may actually be smaller than necessary. #CVE-2023-6857: Symlinks may resolve to smaller than expected buffers Reporter Jed Davis Impact moderate Description This issue could allow an attacker to perform remote code execution and sandbox escape. The WebGL DrawElementsInstanced method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. #CVE-2023-6856: Heap-buffer-overflow affecting WebGL DrawElementsInstanced method with Mesa VM driver Reporter DoHyun Lee Impact high Description This could be used to give recipients the impression that a message was sent at a different date or time. If present, Thunderbird did not compare the signature creation date with the message date and time, and displayed a valid signature despite a date or time mismatch. The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. #CVE-2023-50761: S/MIME signature accepted despite mismatching message date Reporter Marcus Brinkmann Impact high Description A digitally signed text from a different context, such as a signed GIT commit, could be used to spoof an email message. This is because the text was interpreted as a MIME message and the first paragraph was always treated as an email header section. When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. #CVE-2023-50762: Truncated signed text was shown with a valid OpenPGP signature Reporter Marcus Brinkmann Impact high Description Mozilla Foundation Security Advisory 2023-55 Security Vulnerabilities fixed in Thunderbird 115.6 Announced DecemImpact high Products Thunderbird Fixed in
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |