Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

openSUSE Leap 42.3 Security Update: MozillaThunderbird Fixes 16 Issues

opensuse
Calendar Grey June 2, 2019
Dist Opensuse Esm H88
A critical security patch from Fedora resolves 12 vulnerabilities in LibreOffice, improving overall protection.
An update that fixes 16 vulnerabilities is now available.

Description

This update for MozillaThunderbird fixes the following issues:

Mozilla Thunderbird was updated to 60.7.0

* Attachment pane of Write window no longer focussed when attaching files

using a keyboard shortcut

Security issues fixed (MFSA 2019-15 boo#1135824):

* CVE-2018-18511: Cross-origin theft of images with

ImageBitmapRenderingContext

* CVE-2019-11691: Use-after-free in XMLHttpRequest

* CVE-2019-11692: Use-after-free removing listeners in the event listener

manager

* CVE-2019-11693: Buffer overflow in WebGL bufferdata on Linux

* CVE-2019-11694: (Windows only) Uninitialized memory memory leakage in

Windows sandbox

* CVE-2019-11698: Theft of user history data through drag and drop of

hyperlinks to and from bookmarks

* CVE-2019-5798: Out-of-bounds read in Skia

* CVE-2019-7317: Use-after-free in png_image_free of libpng library

* CVE-2019-9797: Cross-origin theft of images with createImageBitmap

* CVE-2019-9800: Memory...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2019-1484=1

Package List

- openSUSE Leap 42.3 (x86_64):

MozillaThunderbird-60.7.0-92.1

MozillaThunderbird-buildsymbols-60.7.0-92.1

MozillaThunderbird-debuginfo-60.7.0-92.1

MozillaThunderbird-debugsource-60.7.0-92.1

MozillaThunderbird-translations-common-60.7.0-92.1

MozillaThunderbird-translations-other-60.7.0-92.1

References

https://www.suse.com/security/cve/CVE-2018-18511.html

https://www.suse.com/security/cve/CVE-2019-11691.html

https://www.suse.com/security/cve/CVE-2019-11692.html

https://www.suse.com/security/cve/CVE-2019-11693.html

https://www.suse.com/security/cve/CVE-2019-11694.html

https://www.suse.com/security/cve/CVE-2019-11698.html

https://www.suse.com/security/cve/CVE-2019-5798.html

https://www.suse.com/security/cve/CVE-2019-7317.html

https://www.suse.com/security/cve/CVE-2019-9797.html

https://www.suse.com/security/cve/CVE-2019-9800.html

https://www.suse.com/security/cve/CVE-2019-9815.html

https://www.suse.com/security/cve/CVE-2019-9816.html

https://www.suse.com/security/cve/CVE-2019-9817.html

https://www.suse.com/security/cve/CVE-2019-9818.html

https://www.suse.com/security/cve/CVE-2019-9819.html

https://www.suse.com/security/cve/CVE-2019-9820.html

https://bugzilla.suse.com/1130694

https://bugzilla.suse.com/1133267

https://bugzilla.suse.com/1135824

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:1484-1
Rating: important
Affected Products: openSUSE Leap 42.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here