This update for MozillaThunderbird to version 52.3 fixes security issues
and bugs.
The following vulnerabilities were fixed:
- CVE-2017-7798: XUL injection in the style editor in devtools
- CVE-2017-7800: Use-after-free in WebSockets during disconnection
- CVE-2017-7801: Use-after-free with marquee during window resizing
- CVE-2017-7784: Use-after-free with image observers - CVE-2017-7802: Use-after-free resizing image elements
- CVE-2017-7785: Buffer overflow manipulating ARIA attributes in DOM
- CVE-2017-7786: Buffer overflow while painting non-displayable SVG
- CVE-2017-7753: Out-of-bounds read with cached style data and
pseudo-elements#
- CVE-2017-7787: Same-origin policy bypass with iframes through page
reloads
- CVE-2017-7807: Domain hijacking through AppCache fallback
- CVE-2017-7792: Buffer overflow viewing certificates with an extremely
long OID
- CVE-2017-7804: Memory protection bypass through...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2017-955=1
- openSUSE Leap 42.2:
zypper in -t patch openSUSE-2017-955=1
To bring your system up-to-date, use "zypper patch".
- openSUSE Leap 42.3 (i586 x86_64):
MozillaThunderbird-52.3.0-44.1
MozillaThunderbird-buildsymbols-52.3.0-44.1
MozillaThunderbird-debuginfo-52.3.0-44.1
MozillaThunderbird-debugsource-52.3.0-44.1
MozillaThunderbird-devel-52.3.0-44.1
MozillaThunderbird-translations-common-52.3.0-44.1
MozillaThunderbird-translations-other-52.3.0-44.1
- openSUSE Leap 42.2 (i586 x86_64):
MozillaThunderbird-52.3.0-41.15.1
MozillaThunderbird-buildsymbols-52.3.0-41.15.1
MozillaThunderbird-debuginfo-52.3.0-41.15.1
MozillaThunderbird-debugsource-52.3.0-41.15.1
MozillaThunderbird-devel-52.3.0-41.15.1
MozillaThunderbird-translations-common-52.3.0-41.15.1
MozillaThunderbird-translations-other-52.3.0-41.15.1
https://www.suse.com/security/cve/CVE-2017-7753.html
https://www.suse.com/security/cve/CVE-2017-7779.html
https://www.suse.com/security/cve/CVE-2017-7782.html
https://www.suse.com/security/cve/CVE-2017-7784.html
https://www.suse.com/security/cve/CVE-2017-7785.html
https://www.suse.com/security/cve/CVE-2017-7786.html
https://www.suse.com/security/cve/CVE-2017-7787.html
https://www.suse.com/security/cve/CVE-2017-7791.html
https://www.suse.com/security/cve/CVE-2017-7792.html
https://www.suse.com/security/cve/CVE-2017-7798.html
https://www.suse.com/security/cve/CVE-2017-7800.html
https://www.suse.com/security/cve/CVE-2017-7801.html
https://www.suse.com/security/cve/CVE-2017-7802.html
https://www.suse.com/security/cve/CVE-2017-7803.html
https://www.suse.com/security/cve/CVE-2017-7804.html
https://www.suse.com/security/cve/CVE-2017-7807.html
https://bugzilla.suse.com/1052829
Get the latest Linux and open source security news straight to your inbox.