Debian has released security updates that fix multiple vulnerabilities in the Thunderbird mail client, twig, and dovecot that lead to DOS, information disclosure, and arbitrary code execution.
DSA-4420 thunderbird
The security update addresses multiple vulnerabilities in the Thunderbird mail client that could allow an attacker to perform arbitrary code execution or denial of service.
The vulnerabilities can be detected as CVE-2018-18506, CVE-2019-9788, CVE-2019-9790, CVE-2019-9791, CVE-2019-9792, CVE-2019-9793, CVE-2019-9795, 2019-9796
All security issues are addressed with version 1:60.6.1-1~deb9u1, so users are advised to update their thunderbird packages.
Twing
Twig is a template engine for PHP and fails to enforce sandboxing resulting in potential information disclosure.
The vulnerability has been fixed with version 1.24.0-2 + deb9u1.

DSA-4418-1 dovecot
The vulnerability is located in the Dovecot email server when reading the FTS or POP3-UIDL headers from the Dovecot index.
Bounds index is not specified, which allows an attacker to modify dovecot indexes, leading to privilege escalation or arbitrary code execution with the privileges of the dovecot user.
Installation using FTS or pop3 migration plugins is affected by the vulnerability and has been patched in version 1: 2.2.27-3 + deb9u4.
You can get the latest security updates using the apt package manager. Before running the apt command, add the repository to your sources list.
Add the file /etc/apt/sources.list and run apt-get update && apt-get upgrade.
