This update for MozillaThunderbird fixes the following issues:
- Mozilla Thunderbird 68.5 (bsc#1162777) MFSA 2020-07 (bsc#1163368)
* CVE-2020-6793 (bmo#1608539) Out-of-bounds read when processing certain
email messages
* CVE-2020-6794 (bmo#1606619) Setting a master password post-Thunderbird
52 does not delete unencrypted previously stored passwords
* CVE-2020-6795 (bmo#1611105) Crash processing S/MIME messages with
multiple signatures
* CVE-2020-6797 (bmo#1596668) Extensions granted downloads.open
permission could open arbitrary applications on Mac OSX
* CVE-2020-6798 (bmo#1602944) Incorrect parsing of template tag could
result in JavaScript injection
* CVE-2020-6792 (bmo#1609607) Message ID calculcation was based on
uninitialized data
* CVE-2020-6800 (bmo#1595786, bmo#1596706, bmo#1598543, bmo#1604851,
bmo#1605777, bmo#1608580, bmo#1608785) Memory safety bugs fixed in
Thunderbird 68.5
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-231=1
- openSUSE Leap 15.1 (x86_64):
MozillaThunderbird-68.5.0-lp151.2.25.1
MozillaThunderbird-debuginfo-68.5.0-lp151.2.25.1
MozillaThunderbird-debugsource-68.5.0-lp151.2.25.1
MozillaThunderbird-translations-common-68.5.0-lp151.2.25.1
MozillaThunderbird-translations-other-68.5.0-lp151.2.25.1
https://www.suse.com/security/cve/CVE-2020-6792.html
https://www.suse.com/security/cve/CVE-2020-6793.html
https://www.suse.com/security/cve/CVE-2020-6794.html
https://www.suse.com/security/cve/CVE-2020-6795.html
https://www.suse.com/security/cve/CVE-2020-6797.html
https://www.suse.com/security/cve/CVE-2020-6798.html
https://www.suse.com/security/cve/CVE-2020-6800.html
https://bugzilla.suse.com/1162777
https://bugzilla.suse.com/1163368
--
Get the latest Linux and open source security news straight to your inbox.