Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

openSUSE Leap 15.2 Important: MozillaThunderbird Mem Safety Update

opensuse
Calendar Grey April 19, 2021
Dist Opensuse Esm H88
Address key vulnerabilities in Mozilla Thunderbird on openSUSE Leap 15.2. Update for improved protection.
An update that fixes 7 vulnerabilities is now available

Description

This update for MozillaThunderbird fixes the following issues:

- Mozilla Thunderbird was updated to version 78.9.1 (MFSA 2021-12,MFSA

2021-13, bsc#1183942, bsc#1184536)

* CVE-2021-23981: Texture upload into an unbound backing buffer resulted

in an out-of-bound read

* CVE-2021-23982: Internal network hosts could have been probed by a

malicious webpage

* CVE-2021-23984: Malicious extensions could have spoofed popup

information

* CVE-2021-23987: Memory safety bugs

* CVE-2021-23991: An attacker may use Thunderbird's OpenPGP key refresh

mechanism to poison an existing key

* CVE-2021-23992: A crafted OpenPGP key with an invalid user ID could be

used to confuse the user

* CVE-2021-23993: Inability to send encrypted OpenPGP email after

importing a crafted OpenPGP key

- cleaned up and fixed mozilla.sh.in for wayland (bsc#1177542)

This update was imported from the SUSE:SLE-15-SP2:Update update...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-580=1

Package List

- openSUSE Leap 15.2 (x86_64):

MozillaThunderbird-78.9.1-lp152.2.38.1

MozillaThunderbird-debuginfo-78.9.1-lp152.2.38.1

MozillaThunderbird-debugsource-78.9.1-lp152.2.38.1

MozillaThunderbird-translations-common-78.9.1-lp152.2.38.1

MozillaThunderbird-translations-other-78.9.1-lp152.2.38.1

References

https://www.suse.com/security/cve/CVE-2021-23981.html

https://www.suse.com/security/cve/CVE-2021-23982.html

https://www.suse.com/security/cve/CVE-2021-23984.html

https://www.suse.com/security/cve/CVE-2021-23987.html

https://www.suse.com/security/cve/CVE-2021-23991.html

https://www.suse.com/security/cve/CVE-2021-23992.html

https://www.suse.com/security/cve/CVE-2021-23993.html

https://bugzilla.suse.com/1177542

https://bugzilla.suse.com/1183942

https://bugzilla.suse.com/1184536

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:0580-1
Rating: important
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here