Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

openSUSE: 2024:4326-1 moderate: Thunderbird path traversal fix

opensuse
Calendar Grey December 16, 2024
Dist Opensuse Esm H88
A patch for LibreOffice resolves security flaws in Ubuntu platforms, promoting safety and improved functionality.
An update that solves one vulnerability can now be installed.

Description

This update for MozillaThunderbird fixes the following issues:

* CVE-2024-50336: Fixed insufficient MXC URI validation which could allow

client-side path traversal (bsc#1234413)

Other fixes: \- Updated to Mozilla Thunderbird 128.5.2i (bsc#1234413): * fixed:

Large virtual folders could be very slow * fixed: Message could disappear after

moving from IMAP folder followed by Undo and Redo * fixed: XMPP chat did not

display messages sent inside a CDATA element * fixed: Selected calendar day did

not move forward at midnight * fixed: Today pane agenda sometimes scrolled for

no apparent reason * fixed: CalDAV calendars without offline support could

degrade start-up performance * fixed: Visual and UX improvements * fixed:

Security fixes

* Updated to Mozilla Thunderbird 128.5.1:

* new: Add end of year donation appeal

* fixed: Total message count for favorite folders did not work consistently

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2024-4326=1

* openSUSE Leap 15.6

zypper in -t patch openSUSE-SLE-15.6-2024-4326=1

* SUSE Package Hub 15 15-SP5

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-4326=1

* SUSE Package Hub 15 15-SP6

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-4326=1

* SUSE Linux Enterprise Workstation Extension 15 SP5

zypper in -t patch SUSE-SLE-Product-WE-15-SP5-2024-4326=1

* SUSE Linux Enterprise Workstation Extension 15 SP6

zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2024-4326=1

Package List

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)

* MozillaThunderbird-debuginfo-128.5.2-150200.8.194.1

* MozillaThunderbird-128.5.2-150200.8.194.1

* MozillaThunderbird-translations-common-128.5.2-150200.8.194.1

* MozillaThunderbird-translations-other-128.5.2-150200.8.194.1

* MozillaThunderbird-debugsource-128.5.2-150200.8.194.1

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)

* MozillaThunderbird-debuginfo-128.5.2-150200.8.194.1

* MozillaThunderbird-128.5.2-150200.8.194.1

* MozillaThunderbird-translations-common-128.5.2-150200.8.194.1

* MozillaThunderbird-translations-other-128.5.2-150200.8.194.1

* MozillaThunderbird-debugsource-128.5.2-150200.8.194.1

* SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x)

* MozillaThunderbird-debuginfo-128.5.2-150200.8.194.1

* MozillaThunderbird-128.5.2-150200.8.194.1

* MozillaThunderbird-translations-common-128.5.2-150200.8.194.1

* MozillaThunderbird-translations-other-128.5.2-150200.8.194.1

* MozillaThunderbird-debugsource-128.5.2-150200.8.194.1

* SUSE Package...

Read the Full Advisory

References

* bsc#1234413

## References:

* https://www.suse.com/security/cve/CVE-2024-50336.html

* https://bugzilla.suse.com/show_bug.cgi?id=1234413

Announcement ID: SUSE-SU-2024:4326-1
Release Date: 2024-12-16T13:11:21Z
Affected Products: * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP5 * SUSE Linux Enterprise Workstation Extension 15 SP6 * SUSE Package Hub 15 15-SP5 * SUSE Package Hub 15 15-SP6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here