Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2020:0142-1 Important: MozillaThunderbird Fixes Multiple Threats

suse
Calendar Grey January 20, 2020
Dist Suse Esm H88
SUSE Security Patch for MozillaFirefox addresses critical security flaws through the release of updated versions.
An update that fixes 7 vulnerabilities is now available

Summary

This update for MozillaThunderbird to version 68.4.1 fixes the following issues: Security issues fixed: - CVE-2019-17026: IonMonkey type confusion with StoreElementHole and FallibleStoreElement - CVE-2019-17016: Bypass of @namespace CSS sanitization during pasting - CVE-2019-17017: Type Confusion in XPCVariant.cpp - CVE-2019-17022: CSS sanitization does not escape HTML tags - CVE-2019-17024: multiple Memory safety bugs fixed Non-security issues fixed: - Various improvements when setting up an account for a Microsoft Exchange server. For example better detection for Office 365 accounts. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

#1160305 #1160498

Cross- CVE-2019-17015 CVE-2019-17016 CVE-2019-17017

CVE-2019-17021 CVE-2019-17022 CVE-2019-17024

CVE-2019-17026

Affected Products:

SUSE Linux Enterprise Workstation Extension 15-SP1

SUSE Linux Enterprise Workstation Extension 15

https://www.suse.com/security/cve/CVE-2019-17015.html

https://www.suse.com/security/cve/CVE-2019-17016.html

https://www.suse.com/security/cve/CVE-2019-17017.html

https://www.suse.com/security/cve/CVE-2019-17021.html

https://www.suse.com/security/cve/CVE-2019-17022.html

https://www.suse.com/security/cve/CVE-2019-17024.html

https://www.suse.com/security/cve/CVE-2019-17026.html

https://bugzilla.suse.com/1160305

https://bugzilla.suse.com/1160498

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:0142-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here