Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

openSUSE Leap 15.0: 2019:1162-1 Important MozillaThunderbird Fix

opensuse
Calendar Grey April 5, 2019
Dist Opensuse Esm H88
A significant update for openSUSE Security tackles 17 vulnerabilities in MozillaFirefox, improving overall protection and performance.
An update that fixes 16 vulnerabilities is now available.

Description

This update for MozillaThunderbird to version 60.5.1 fixes the following

issues:

Security issues fixed:

- Update to MozillaThunderbird 60.6.1 (bsc#1130262):

- CVE-2019-9813: Fixed Ionmonkey type confusion with __proto__ mutations

- CVE-2019-9810: Fixed IonMonkey MArraySlice incorrect alias information

- Update to MozillaThunderbird 60.6 (bsc#1129821):

- CVE-2018-18506: Fixed an issue with Proxy Auto-Configuration file

- CVE-2019-9801: Fixed an issue which could allow Windows programs to be

exposed to web content

- CVE-2019-9788: Fixed multiple memory safety bugs

- CVE-2019-9790: Fixed a Use-after-free vulnerability when removing in-use

DOM elements

- CVE-2019-9791: Fixed an incorrect Type inference for constructors entered through on-stack replacement with IonMonkey

- CVE-2019-9792: Fixed an issue where IonMonkey leaks JS_OPTIMIZED_OUT

magic value to script

- CVE-2019-9793: Fixed multiple improper bounds checks when...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2019-1162=1

Package List

- openSUSE Leap 15.0 (x86_64):

MozillaThunderbird-60.6.1-lp150.3.37.1

MozillaThunderbird-buildsymbols-60.6.1-lp150.3.37.1

MozillaThunderbird-debuginfo-60.6.1-lp150.3.37.1

MozillaThunderbird-debugsource-60.6.1-lp150.3.37.1

MozillaThunderbird-translations-common-60.6.1-lp150.3.37.1

MozillaThunderbird-translations-other-60.6.1-lp150.3.37.1

References

https://www.suse.com/security/cve/CVE-2018-18335.html

https://www.suse.com/security/cve/CVE-2018-18356.html

https://www.suse.com/security/cve/CVE-2018-18506.html

https://www.suse.com/security/cve/CVE-2018-18509.html

https://www.suse.com/security/cve/CVE-2019-5785.html

https://www.suse.com/security/cve/CVE-2019-9788.html

https://www.suse.com/security/cve/CVE-2019-9790.html

https://www.suse.com/security/cve/CVE-2019-9791.html

https://www.suse.com/security/cve/CVE-2019-9792.html

https://www.suse.com/security/cve/CVE-2019-9793.html

https://www.suse.com/security/cve/CVE-2019-9794.html

https://www.suse.com/security/cve/CVE-2019-9795.html

https://www.suse.com/security/cve/CVE-2019-9796.html

https://www.suse.com/security/cve/CVE-2019-9801.html

https://www.suse.com/security/cve/CVE-2019-9810.html

https://www.suse.com/security/cve/CVE-2019-9813.html

https://bugzilla.suse.com/1125330

https://bugzilla.suse.com/1129821

https://bugzilla.suse.com/1130262

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:1162-1
Rating: important
Affected Products: openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here