Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

openSUSE Leap 15.0: 2019:2464-1 Important: Firefox Heap Overflow Fix

opensuse
Calendar Grey November 9, 2019
Dist Opensuse Esm H88
Essential openSUSE notice addresses 7 significant vulnerabilities within MozillaFirefox; vital patch provides improved protection.
An update that fixes 9 vulnerabilities is now available.

Description

This update for MozillaThunderbird to version 68.2.1 provides the

following fixes:

- Security issues fixed (bsc#1154738):

* CVE-2019-15903: Fixed a heap overflow in the expat library

(bsc#1149429).

* CVE-2019-11757: Fixed a use-after-free when creating index updates in

IndexedDB (bsc#1154738).

* CVE-2019-11758: Fixed a potentially exploitable crash due to 360 Total

Security (bsc#1154738).

* CVE-2019-11759: Fixed a stack buffer overflow in HKDF output

(bsc#1154738).

* CVE-2019-11760: Fixed a stack buffer overflow in WebRTC networking

(bsc#1154738).

* CVE-2019-11761: Fixed an unintended access to a privileged JSONView

object (bsc#1154738).

* CVE-2019-11762: Fixed a same-origin-property violation (bsc#1154738).

* CVE-2019-11763: Fixed an XSS bypass (bsc#1154738).

* CVE-2019-11764: Fixed several memory safety bugs (bsc#1154738).

Other fixes (bsc#1153879):

* Some attachments couldn't...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2019-2464=1

Package List

- openSUSE Leap 15.0 (x86_64):

MozillaThunderbird-68.2.1-lp150.3.54.1

MozillaThunderbird-debuginfo-68.2.1-lp150.3.54.1

MozillaThunderbird-debugsource-68.2.1-lp150.3.54.1

MozillaThunderbird-translations-common-68.2.1-lp150.3.54.1

MozillaThunderbird-translations-other-68.2.1-lp150.3.54.1

References

https://www.suse.com/security/cve/CVE-2019-11757.html

https://www.suse.com/security/cve/CVE-2019-11758.html

https://www.suse.com/security/cve/CVE-2019-11759.html

https://www.suse.com/security/cve/CVE-2019-11760.html

https://www.suse.com/security/cve/CVE-2019-11761.html

https://www.suse.com/security/cve/CVE-2019-11762.html

https://www.suse.com/security/cve/CVE-2019-11763.html

https://www.suse.com/security/cve/CVE-2019-11764.html

https://www.suse.com/security/cve/CVE-2019-15903.html

https://bugzilla.suse.com/1149126

https://bugzilla.suse.com/1149429

https://bugzilla.suse.com/1151186

https://bugzilla.suse.com/1152778

https://bugzilla.suse.com/1153879

https://bugzilla.suse.com/1154738

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:2464-1
Rating: important
Affected Products: openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here