Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

openSUSE: 2016:1769-1 Important: Mozilla Thunderbird Memory Threat

opensuse
Calendar Grey July 11, 2016
Scroller Opensuse
Fixes address 28 security holes in Mozilla Thunderbird with a crucial update for SUSE Linux Enterprise environments.
An update that fixes 28 vulnerabilities is now available

Description

This update contains Mozilla Thunderbird 45.2. (boo#983549)

It fixes security issues mostly affecting the e-mail program when used in

a browser context, such as viewing a web page or HTMl formatted e-mail.

The following vulnerabilities were fixed:

- CVE-2016-2818, CVE-2016-2815: Memory safety bugs (boo#983549,

MFSA2016-49)

Contains the following security fixes from the 45.1 release: (boo#977333)

- CVE-2016-2806, CVE-2016-2807: Miscellaneous memory safety hazards

(boo#977375, boo#977376, MFSA 2016-39)

Contains the following security fixes from the 45.0 release: (boo#969894)

- CVE-2016-1952, CVE-2016-1953: Miscellaneous memory safety hazards (MFSA

2016-16)

- CVE-2016-1954: Local file overwriting and potential privilege escalation

through CSP reports (MFSA 2016-17)

- CVE-2016-1955: CSP reports fail to strip location information for

embedded iframe pages (MFSA 2016-18)

- CVE-2016-1956: Linux video memory DOS with Intel...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2016-851=1

To bring your system up-to-date, use "zypper patch".

Package List

- SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 s390x x86_64):

MozillaThunderbird-45.2-6.1

MozillaThunderbird-debuginfo-45.2-6.1

MozillaThunderbird-debugsource-45.2-6.1

MozillaThunderbird-devel-45.2-6.1

MozillaThunderbird-translations-common-45.2-6.1

MozillaThunderbird-translations-other-45.2-6.1

- SUSE Package Hub for SUSE Linux Enterprise 12 (x86_64):

MozillaThunderbird-buildsymbols-45.2-6.1

References

https://www.suse.com/security/cve/CVE-2016-1952.html

https://www.suse.com/security/cve/CVE-2016-1953.html

https://www.suse.com/security/cve/CVE-2016-1954.html

https://www.suse.com/security/cve/CVE-2016-1955.html

https://www.suse.com/security/cve/CVE-2016-1956.html

https://www.suse.com/security/cve/CVE-2016-1957.html

https://www.suse.com/security/cve/CVE-2016-1960.html

https://www.suse.com/security/cve/CVE-2016-1961.html

https://www.suse.com/security/cve/CVE-2016-1964.html

https://www.suse.com/security/cve/CVE-2016-1974.html

https://www.suse.com/security/cve/CVE-2016-1977.html

https://www.suse.com/security/cve/CVE-2016-2790.html

https://www.suse.com/security/cve/CVE-2016-2791.html

https://www.suse.com/security/cve/CVE-2016-2792.html

https://www.suse.com/security/cve/CVE-2016-2793.html

https://www.suse.com/security/cve/CVE-2016-2794.html

https://www.suse.com/security/cve/CVE-2016-2795.html

https://www.suse.com/security/cve/CVE-2016-2796.html

https://www.suse.com/security/cve/CVE-2016-2797.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:1769-1
Rating: important
Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.