Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

openSUSE: 2019:2248-1 Critical Update: Mozilla Thunderbird Security Fixes

opensuse
Calendar Grey October 4, 2019
Dist Opensuse Esm H88
This critical notification highlights 25 vulnerability fixes in MozillaFirefox for Fedora, boosting application security and resilience.
An update that fixes 27 vulnerabilities is now available.

Description

This update for MozillaThunderbird to version 68.1.1 fixes the following

issues:

- CVE-2019-11709: Fixed several memory safety bugs. (bsc#1140868)

- CVE-2019-11710: Fixed several memory safety bugs. (bsc#1140868)

- CVE-2019-11711: Fixed a script injection within domain through inner

window reuse. (bsc#1140868)

- CVE-2019-11712: Fixed an insufficient validation of cross-origin POST

requests within NPAPI plugins. (bsc#1140868)

- CVE-2019-11713: Fixed a use-after-free with HTTP/2 cached stream.

(bsc#1140868)

- CVE-2019-11714: Fixed a crash in NeckoChild. (bsc#1140868)

- CVE-2019-11715: Fixed an HTML parsing error that can contribute to

content XSS. (bsc#1140868)

- CVE-2019-11716: Fixed an enumeration issue in globalThis. (bsc#1140868)

- CVE-2019-11717: Fixed an improper escaping of the caret character in

origins. (bsc#1140868)

- CVE-2019-11719: Fixed an out-of-bounds read when importing curve25519

private key....

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2019-2248=1

Package List

- openSUSE Leap 15.0 (x86_64):

MozillaThunderbird-68.1.1-lp150.3.51.1

MozillaThunderbird-buildsymbols-68.1.1-lp150.3.51.1

MozillaThunderbird-debuginfo-68.1.1-lp150.3.51.1

MozillaThunderbird-debugsource-68.1.1-lp150.3.51.1

MozillaThunderbird-translations-common-68.1.1-lp150.3.51.1

MozillaThunderbird-translations-other-68.1.1-lp150.3.51.1

enigmail-2.1.2-lp150.34.1

References

https://www.suse.com/security/cve/CVE-2019-11709.html

https://www.suse.com/security/cve/CVE-2019-11710.html

https://www.suse.com/security/cve/CVE-2019-11711.html

https://www.suse.com/security/cve/CVE-2019-11712.html

https://www.suse.com/security/cve/CVE-2019-11713.html

https://www.suse.com/security/cve/CVE-2019-11714.html

https://www.suse.com/security/cve/CVE-2019-11715.html

https://www.suse.com/security/cve/CVE-2019-11716.html

https://www.suse.com/security/cve/CVE-2019-11717.html

https://www.suse.com/security/cve/CVE-2019-11719.html

https://www.suse.com/security/cve/CVE-2019-11720.html

https://www.suse.com/security/cve/CVE-2019-11721.html

https://www.suse.com/security/cve/CVE-2019-11723.html

https://www.suse.com/security/cve/CVE-2019-11724.html

https://www.suse.com/security/cve/CVE-2019-11725.html

https://www.suse.com/security/cve/CVE-2019-11727.html

https://www.suse.com/security/cve/CVE-2019-11728.html

https://www.suse.com/security/cve/CVE-2019-11729.html

https://www.suse.com/security/cve/CVE-2019-117...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:2248-1
Rating: important
Affected Products: openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here