Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 513
Alerts This Week
Warning Icon 1 513

SUSE 15-SP2: SUSE-SU-2020:3935-1 Critical Security for Mozilla Thunderbird

suse
Calendar Grey December 25, 2020
Scroller Suse
Important patch for MozillaThunderbird on SUSE tackling major vulnerabilities and boosting protective protocols.
An update that fixes 9 vulnerabilities is now available

Summary

This update for MozillaThunderbird fixes the following issues: - Mozilla Thunderbird 78.6 * new: MailExtensions: Added browser.windows.openDefaultBrowser() (bmo#1664708) * changed: Thunderbird now only shows quota exceeded indications on the main window (bmo#1671748) * changed: MailExtensions: menus API enabled in messages being composed (bmo#1670832) * changed: MailExtensions: Honor allowScriptsToClose argument in windows.create API function (bmo#1675940) * changed: MailExtensions: APIs that returned an accountId will reflect the account the message belongs to, not what is stored in message headers (bmo#1644032) * fixed: Keyboard shortcut for toggling message "read" status not shown in menus (bmo#1619248) * fixed: OpenPGP: After importing a secret key, Key Manager displayed

References

#1179530 #1180039

Cross- CVE-2020-16042 CVE-2020-26970 CVE-2020-26971

CVE-2020-26973 CVE-2020-26974 CVE-2020-26978

CVE-2020-35111 CVE-2020-35112 CVE-2020-35113

Affected Products:

SUSE Linux Enterprise Workstation Extension 15-SP2

https://www.suse.com/security/cve/CVE-2020-16042.html

https://www.suse.com/security/cve/CVE-2020-26970.html

https://www.suse.com/security/cve/CVE-2020-26971.html

https://www.suse.com/security/cve/CVE-2020-26973.html

https://www.suse.com/security/cve/CVE-2020-26974.html

https://www.suse.com/security/cve/CVE-2020-26978.html

https://www.suse.com/security/cve/CVE-2020-35111.html

https://www.suse.com/security/cve/CVE-2020-35112.html

https://www.suse.com/security/cve/CVE-2020-35113.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3935-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.