An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Security update for MozillaThunderbird ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1392-1 Rating: important References: #1175686 Cross-References: CVE-2020-15663 CVE-2020-15664 CVE-2020-15669 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for MozillaThunderbird fixes the following issues: - Mozilla Thunderbird was updated to 68.12 (bsc#1175686) - CVE-2020-15663: Downgrade attack on the Mozilla Maintenance Service could have resulted in escalation of privilege - CVE-2020-15664: Attacker-induced prompt for extension installation - CVE-2020-15669: Use-After-Free when aborting an operation This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-1392=1 Package List: - openSUSE Leap 15.2 (x86_64): MozillaThunderbird-68.12.0-lp152.2.10.1 MozillaThunderbird-debuginfo-68.12.0-lp152.2.10.1 MozillaThunderbird-debugsource-68.12.0-lp152.2.10.1 MozillaThunderbird-translations-common-68.12.0-lp152.2.10.1 MozillaThunderbird-translations-other-68.12.0-lp152.2.10.1 References: https://www.suse.com/security/cve/CVE-2020-15663.html https://www.suse.com/security/cve/CVE-2020-15664.html https://www.suse.com/security/cve/CVE-2020-15669.html https://bugzilla.suse.com/1175686 -- . Important security patch for Mozilla Thunderbird addresses three security flaws in openSUSELeap 15.2 along with installation instructions.. MozillaThunderbird Update, openSUSE Security, Privilege Escalation Fix, Installation Prompt Issue. . Severity: Important. LinuxSecurity.com Team
Mozilla: Attacker-induced prompt for extension installation (CVE-2020-15664) * Mozilla: Use-After-Free when aborting an operation (CVE-2020-15669) SL6 x86_64 firefox-68.12.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.12.0-1.el6_10.x86_64.rpm firefox-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm i386 firefox-68.12.0-1.el6_10.i686.rpm firefox-d [More...]. Synopsis: Important: firefox security update Advisory ID: SLSA-2020:3558-1 Issue Date: 2020-08-26 CVE Numbers: None -- Security Fix(es): * Mozilla: Attacker-induced prompt for extension installation (CVE-2020-15664) * Mozilla: Use-After-Free when aborting an operation (CVE-2020-15669) -- SL6 x86_64 firefox-68.12.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.12.0-1.el6_10.x86_64.rpm firefox-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm i386 firefox-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm - Scientific Linux Development Team . Crucial updates for Firefox address issues surrounding extension management and the exploitation of use-after-free vulnerabilities in SL6.x.. firefox security update, SL6 important, installation prompt, use-after-free fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.