Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

openSUSE: 2015:1679-1 Critical: MozillaThunderbird Multiple Security Issues

opensuse
Calendar Grey October 5, 2015
Scroller Opensuse
Essential security patch for Mozilla Thunderbird on openSUSE, tackling various vulnerabilities and improving overall performance.
An update that fixes 17 vulnerabilities is now available

Description

MozillaThunderbird was updated to fix 17 security issues.

These security issues were fixed:

- CVE-2015-4509: Use-after-free vulnerability in the HTMLVideoElement

interface in Mozilla Firefox before 41.0 and Firefox ESR 38.x before

38.3 allowed remote attackers to execute arbitrary code via crafted

JavaScript code that modifies the URI table of a media element, aka

ZDI-CAN-3176 (bsc#947003).

- CVE-2015-4520: Mozilla Firefox before 41.0 and Firefox ESR 38.x before

38.3 allowed remote attackers to bypass CORS preflight protection

mechanisms by leveraging (1) duplicate cache-key generation or (2)

retrieval of a value from an incorrect HTTP Access-Control-* response

header (bsc#947003).

- CVE-2015-4521: The ConvertDialogOptions function in Mozilla Firefox

before 41.0 and Firefox ESR 38.x before 38.3 might allowed remote

attackers to cause a denial of service (memory corruption and

application crash) or possibly have...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:

zypper in -t patch openSUSE-2015-631=1

- openSUSE 13.1:

zypper in -t patch openSUSE-2015-631=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 (i586 x86_64):

MozillaThunderbird-38.3.0-28.1

MozillaThunderbird-buildsymbols-38.3.0-28.1

MozillaThunderbird-debuginfo-38.3.0-28.1

MozillaThunderbird-debugsource-38.3.0-28.1

MozillaThunderbird-devel-38.3.0-28.1

MozillaThunderbird-translations-common-38.3.0-28.1

MozillaThunderbird-translations-other-38.3.0-28.1

- openSUSE 13.1 (i586 x86_64):

MozillaThunderbird-38.3.0-70.65.1

MozillaThunderbird-buildsymbols-38.3.0-70.65.1

MozillaThunderbird-debuginfo-38.3.0-70.65.1

MozillaThunderbird-debugsource-38.3.0-70.65.1

MozillaThunderbird-devel-38.3.0-70.65.1

MozillaThunderbird-translations-common-38.3.0-70.65.1

MozillaThunderbird-translations-other-38.3.0-70.65.1

References

https://www.suse.com/security/cve/CVE-2015-4500.html

https://www.suse.com/security/cve/CVE-2015-4505.html

https://www.suse.com/security/cve/CVE-2015-4506.html

https://www.suse.com/security/cve/CVE-2015-4509.html

https://www.suse.com/security/cve/CVE-2015-4511.html

https://www.suse.com/security/cve/CVE-2015-4517.html

https://www.suse.com/security/cve/CVE-2015-4519.html

https://www.suse.com/security/cve/CVE-2015-4520.html

https://www.suse.com/security/cve/CVE-2015-4521.html

https://www.suse.com/security/cve/CVE-2015-4522.html

https://www.suse.com/security/cve/CVE-2015-7174.html

https://www.suse.com/security/cve/CVE-2015-7175.html

https://www.suse.com/security/cve/CVE-2015-7176.html

https://www.suse.com/security/cve/CVE-2015-7177.html

https://www.suse.com/security/cve/CVE-2015-7178.html

https://www.suse.com/security/cve/CVE-2015-7179.html

https://www.suse.com/security/cve/CVE-2015-7180.html

https://bugzilla.suse.com/show_bug.cgi?id=947003

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:1679-1
Rating: important
Affected Products: openSUSE 13.2 openSUSE 13.1 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.