Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2024:2415-1 Moderate: MozillaThunderbird Denial of Service Threat

suse
Calendar Grey July 12, 2024
Dist Suse Esm H88
Critical security enhancement released for Mozilla Firefox. Apply updates to resolve buffer overflow vulnerability. Review further information!
* bsc#1226495 * bsc#1227239 Cross-References: * CVE-2024-34703

Summary

## This update for MozillaThunderbird fixes the following issues: Security fixes: * CVE-2024-34703: Fixed denial of service due to overly large elliptic curve parameters in Botan (bsc#1227239) Other fixes: * Mozilla Thunderbird 115.12.1 * 115.12.0 got pulled because of upstream automation process errors and Windows installer signing changes. No code changes, changelog is the same as 115.12.0 (bsc#1226495) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-2415=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-2415=1 * SUSE Package Hub 15 15-SP5

References

* bsc#1226495

* bsc#1227239

Cross-

* CVE-2024-34703

CVSS scores:

* CVE-2024-34703 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products:

* openSUSE Leap 15.5

* openSUSE Leap 15.6

* SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4

* SUSE Linux Enterprise Desktop 15 SP5

* SUSE Linux Enterprise Desktop 15 SP6

* SUSE Linux Enterprise High Performance Computing 15 SP5

* SUSE Linux Enterprise Micro 5.5

* SUSE Linux Enterprise Real Time 15 SP5

* SUSE Linux Enterprise Real Time 15 SP6

* SUSE Linux Enterprise Server 15 SP5

* SUSE Linux Enterprise Server 15 SP6

* SUSE Linux Enterprise Server for SAP Applications 15 SP5

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

* SUSE Linux Enterprise Workstation Extension 15 SP5

* SUSE Linux Enterprise Workstation Extension 15 SP6

* SUSE Package Hub 15 15-SP5

Announcement ID: SUSE-SU-2024:2415-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here