An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.. openSUSE Security Update: Security update for Mozilla Thunderbird ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:3433-1 Rating: important References: #1074043 #1074044 #1074045 #1074046 Cross-References: CVE-2017-7829 CVE-2017-7846 CVE-2017-7847 CVE-2017-7848 Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for Mozilla Thunderbird to version 52.5.2 fixes the following vulnerabilities: - CVE-2017-7846: JavaScript Execution via RSS in mailbox:// origin (bsc#1074043) - CVE-2017-7847: Local path string can be leaked from RSS feed (bsc#1074044) - CVE-2017-7848: RSS Feed vulnerable to new line Injection (bsc#1074045) - CVE-2017-7829: From address with encoded null character is cut off in message header display (bsc#1074046) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Package Hub for SUSE Linux Enterprise 12: zypper in -t patch openSUSE-2017-1419=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Package Hub for SUSE Linux Enterprise 12 (x86_64): MozillaThunderbird-52.5.2-51.1 MozillaThunderbird-buildsymbols-52.5.2-51.1 MozillaThunderbird-debuginfo-52.5.2-51.1 MozillaThunderbird-debugsource-52.5.2-51.1 MozillaThunderbird-devel-52.5.2-51.1 MozillaThunderbird-translations-common-52.5.2-51.1 MozillaThunderbird-translations-other-52.5.2-51.1 References: https://www.suse.com/security/cve/CVE-2017-7829.html https://www.suse.com/security/cve/CVE-2017-7846.html https://www.suse.com/security/cve/CVE-2017-7847.html https://www.suse.com/security/cve/CVE-2017-7848.html https://bugzilla.suse.com/1074043 https://bugzilla.suse.com/1074044 https://bugzilla.suse.com/1074045 https://bugzilla.suse.com/1074046 . Mozilla Thunderbird has released a crucial update that resolves several major concerns. Ensure your security by updating without delay.. Mozilla Thunderbird Update, openSUSE Security, Patch Instructions, Software Vulnerabilities, Security Issues. . Severity: Important. LinuxSecurity.com Team
An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.. openSUSE Security Update: Security update for Mozilla Thunderbird ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:3434-1 Rating: important References: #1074043 #1074044 #1074045 #1074046 Cross-References: CVE-2017-7829 CVE-2017-7846 CVE-2017-7847 CVE-2017-7848 Affected Products: openSUSE Leap 42.3 openSUSE Leap 42.2 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for Mozilla Thunderbird to version 52.5.2 fixes the following vulnerabilities: - CVE-2017-7846: JavaScript Execution via RSS in mailbox:// origin (bsc#1074043) - CVE-2017-7847: Local path string can be leaked from RSS feed (bsc#1074044) - CVE-2017-7848: RSS Feed vulnerable to new line Injection (bsc#1074045) - CVE-2017-7829: From address with encoded null character is cut off in message header display (bsc#1074046) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2017-1419=1 - openSUSE Leap 42.2: zypper in -t patch openSUSE-2017-1419=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.3 (i586 x86_64): MozillaThunderbird-52.5.2-53.1 MozillaThunderbird-buildsymbols-52.5.2-53.1 MozillaThunderbird-debuginfo-52.5.2-53.1 MozillaThunderbird-debugsource-52.5.2-53.1 MozillaThunderbird-devel-52.5.2-53.1 MozillaThunderbird-translations-common-52.5.2-53.1 MozillaThunderbird-translations-other-52.5.2-53.1 -openSUSE Leap 42.2 (i586 x86_64): MozillaThunderbird-52.5.2-41.24.1 MozillaThunderbird-buildsymbols-52.5.2-41.24.1 MozillaThunderbird-debuginfo-52.5.2-41.24.1 MozillaThunderbird-debugsource-52.5.2-41.24.1 MozillaThunderbird-devel-52.5.2-41.24.1 MozillaThunderbird-translations-common-52.5.2-41.24.1 MozillaThunderbird-translations-other-52.5.2-41.24.1 References: https://www.suse.com/security/cve/CVE-2017-7829.html https://www.suse.com/security/cve/CVE-2017-7846.html https://www.suse.com/security/cve/CVE-2017-7847.html https://www.suse.com/security/cve/CVE-2017-7848.html https://bugzilla.suse.com/1074043 https://bugzilla.suse.com/1074044 https://bugzilla.suse.com/1074045 https://bugzilla.suse.com/1074046 . Crucial notice for Mozilla Thunderbird users on openSUSE regarding multiple security flaws. Protect your system immediately.. Mozilla Thunderbird Update, openSUSE Security, RSS Exploit Fixes. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.