Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

SUSE: 2018:2174-1 Moderate: Mozilla Thunderbird Security Fixes

suse
Calendar Grey August 2, 2018
Scroller Suse
SUSE Security Advisory: Mozilla Firefox Update Addressing 12 Vulnerabilities and Improvements.
An update that fixes 11 vulnerabilities is now available

Summary

This update for Mozilla Thunderbird to version 52.9.1 fixes multiple issues. Security issues fixed, inherited from the Mozilla common code base (MFSA 2018-16, bsc#1098998): - CVE-2018-12359: Buffer overflow using computed size of canvas element - CVE-2018-12360: Use-after-free when using focus() - CVE-2018-12362: Integer overflow in SSSE3 scaler - CVE-2018-12363: Use-after-free when appending DOM nodes - CVE-2018-12364: CSRF attacks through 307 redirects and NPAPI plugins - CVE-2018-12365: Compromised IPC child process can list local filenames - CVE-2018-12366: Invalid data handling during QCMS transformations - CVE-2018-5188: Memory safety bugs fixed in Thunderbird 52.9.0 Security issues fixed that affect e-mail privacy and integrity (including EFAIL):

References

#1076907 #1085780 #1091376 #1098998 #1100079

#1100081 #1100082 #1100780

Cross- CVE-2018-12359 CVE-2018-12360 CVE-2018-12362

CVE-2018-12363 CVE-2018-12364 CVE-2018-12365

CVE-2018-12366 CVE-2018-12372 CVE-2018-12373

CVE-2018-12374 CVE-2018-5188

Affected Products:

SUSE Linux Enterprise Workstation Extension 15

https://www.suse.com/security/cve/CVE-2018-12359.html

https://www.suse.com/security/cve/CVE-2018-12360.html

https://www.suse.com/security/cve/CVE-2018-12362.html

https://www.suse.com/security/cve/CVE-2018-12363.html

https://www.suse.com/security/cve/CVE-2018-12364.html

https://www.suse.com/security/cve/CVE-2018-12365.html

https://www.suse.com/security/cve/CVE-2018-12366.html

Announcement ID: SUSE-SU-2018:2174-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.