Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2019:1495-1 Important: MozillaThunderbird Buffer Overflow Issues

suse
Calendar Grey June 14, 2019
Dist Suse Esm H88
SUSE has released a critical security update for Mozilla Thunderbird. Ensure your safety by reviewing this advisory.
An update that fixes four vulnerabilities is now available

Summary

This update for MozillaThunderbird fixes the following security issues: - CVE-2019-11703: Fixed a heap-based buffer overflow in icalmemorystrdupanddequote() (bsc#1137595). - CVE-2019-11704: Fixed a heap-based buffer overflow in parser_get_next_char() (bsc#1137595). - CVE-2019-11705: Fixed a stack-based buffer overflow in icalrecur_add_bydayrules() (bsc#1137595). - CVE-2019-11706: Fixed a type confusion in icaltimezone_get_vtimezone_properties() (bsc#1137595). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15-SP1: zypper in -t patch SUSE-SLE-Product-WE-15-SP1-2019-1495=1

References

#1137595

Cross- CVE-2019-11703 CVE-2019-11704 CVE-2019-11705

CVE-2019-11706

Affected Products:

SUSE Linux Enterprise Workstation Extension 15-SP1

SUSE Linux Enterprise Workstation Extension 15

https://www.suse.com/security/cve/CVE-2019-11703.html

https://www.suse.com/security/cve/CVE-2019-11704.html

https://www.suse.com/security/cve/CVE-2019-11705.html

https://www.suse.com/security/cve/CVE-2019-11706.html

https://bugzilla.suse.com/1137595

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1495-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here