## This update for MozillaThunderbird fixes the following issues: Update to Mozilla Thunderbird 115.7 (MFSA 2024-04) (bsc#1218955): * CVE-2024-0741: Out of bounds write in ANGLE * CVE-2024-0742: Failure to update user input timestamp * CVE-2024-0746: Crash when listing printers on Linux * CVE-2024-0747: Bypass of Content Security Policy when directive unsafe- inline was set * CVE-2024-0749: Phishing site popup could show local origin in address bar * CVE-2024-0750: Potential permissions request bypass via clickjacking * CVE-2024-0751: Privilege escalation through devtools * CVE-2024-0753: HSTS policy on subdomain could bypass policy of upper domain * CVE-2024-0755: Memory safety bugs fixed in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7 Other fixes:
* bsc#1218955
Cross-
* CVE-2024-0741
* CVE-2024-0742
* CVE-2024-0746
* CVE-2024-0747
* CVE-2024-0749
* CVE-2024-0750
* CVE-2024-0751
* CVE-2024-0753
* CVE-2024-0755
CVSS scores:
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4
* SUSE Linux Enterprise Desktop 15 SP5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Real Time 15 SP5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Workstation Extension 15 SP5
* SUSE Package Hub 15 15-SP5
An update that solves nine vulnerabilities can now be installed.
##
* https://www.suse.com/security/cve/CVE-2024-0741.html
* https://www.suse.com/security/cve/CVE-2024-0742.html
Get the latest Linux and open source security news straight to your inbox.