Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2019:1458-1 Important: MozillaThunderbird Buffer Overflow

suse
Calendar Grey June 11, 2019
Dist Suse Esm H88
SUSE has released a Security Update addressing 16 critical vulnerabilities in MozillaThunderbird, categorized with important severity. Further information on these issues can be found within.
An update that fixes 16 vulnerabilities is now available

Summary

This update for MozillaThunderbird fixes the following issues: Mozilla Thunderbird was updated to 60.7.0. * Attachment pane of Write window no longer focussed when attaching files using a keyboard shortcut These security issues were fixed (MFSA 2019-15 bsc#1135824): * CVE-2019-9815: Disable hyperthreading on content JavaScript threads on macOS * CVE-2019-9816: Type confusion with object groups and UnboxedObjects * CVE-2019-9817: Stealing of cross-domain images using canvas * CVE-2019-9818: Use-after-free in crash generation server * CVE-2019-9819: Compartment mismatch with fetch API * CVE-2019-9820: Use-after-free of ChromeEventHandler by DocShell * CVE-2019-11691: Use-after-free in XMLHttpRequest * CVE-2019-11692: Use-after-free removing listeners in the event listener manager

References

#1130694 #1133267 #1135824

Cross- CVE-2018-18511 CVE-2019-11691 CVE-2019-11692

CVE-2019-11693 CVE-2019-11694 CVE-2019-11698

CVE-2019-5798 CVE-2019-7317 CVE-2019-9797

CVE-2019-9800 CVE-2019-9815 CVE-2019-9816

CVE-2019-9817 CVE-2019-9818 CVE-2019-9819

CVE-2019-9820

Affected Products:

SUSE Linux Enterprise Workstation Extension 15-SP1

SUSE Linux Enterprise Workstation Extension 15

https://www.suse.com/security/cve/CVE-2018-18511.html

https://www.suse.com/security/cve/CVE-2019-11691.html

https://www.suse.com/security/cve/CVE-2019-11692.html

https://www.suse.com/security/cve/CVE-2019-11693.html

https://www.suse.com/security/cve/CVE-2019-11694.html

https://www.suse.com/security/cve/CVE-2019-11698.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1458-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here