Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 512
Alerts This Week
Warning Icon 1 512

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
89

Fedora 43 libpng Addresses Medium Severity Memory Bug CVE-2026-34757

updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a109a9ac2c 2026-06-02 01:10:43.197462+00:00 -------------------------------------------------------------------------------- Name : libpng Product : Fedora 43 Version : 1.6.58 Release : 1.fc43 URL : http://www.libpng.org/pub/png/ Summary : A library of functions for manipulating PNG image format files Description : The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. PNG is a bit-mapped graphics format similar to the GIF format. PNG was created to replace the GIF format, since GIF uses a patented data compression algorithm. Libpng should be installed if you need to manipulate PNG format image files. -------------------------------------------------------------------------------- Update Information: updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the fix for CVE-2026-33416 in 1.6.56. 1.6.57 is released with fixes for the following security vulnerability: CVE-2026-34757 (medium severity): Use-after-free memory bug in the chunk setter API. The hIST variant has existed since version 1.0.9, but the PLTE and tRNS ones are regressions introduced in the fix for CVE-2026-33416 in 1.6.56(oops). -------------------------------------------------------------------------------- ChangeLog: * Thu May 21 2026 Michal Hlavinka - 2:1.6.58-1 - updated to 1.6.58 (#2456815) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2460625 - CVE-2026-22020 libpng: OpenJDK: Update LibPNG (Oracle CPU 2026-04) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460625 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a109a9ac2c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fix for medium severity memory bug in libpng 1.6.58 for Fedora 43 addresses regressions and improves functionality.. libpng update, Fedora security advisory, medium severity fix, memory issue, libpng 1.6.58. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jun 02, 2026 Medium Fedora
202

Fedora 38 Ultimate Java - Simplified Deployment for Fedora-XYZ-2024-30002-5

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for python-orjson ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20407-1 Rating: moderate References: * bsc#1257121 Cross-References: * CVE-2025-67221 CVSS scores: * CVE-2025-67221 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67221 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for python-orjson fixes the following issues: - CVE-2025-67221: Fixed write outsize of allocated memory on json dump (bsc#1257121). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-421=1 Package List: - openSUSE Leap 16.0: python313-orjson-3.10.15-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2025-67221.html . This security update addresses a moderate issue in python-orjson on openSUSE Leap 16.0, with details on the fix provided.. python orjson, openSUSE update, memory bug fix. . LinuxSecurity.com Team

Calendar%202 Mar 28, 2026 OpenSUSE
219

Rocky Linux 9 RLSA-2023:1337 Important: Firefox Memory Bugs

Important: firefox security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:1337", "synopsis": "Important: firefox security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for firefox.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.\n\nThis update upgrades Firefox to version 102.9.0 ESR.\n\nSecurity Fix(es):\n\n* Mozilla: Incorrect code generation during JIT compilation (CVE-2023-25751)\n\n* Mozilla: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9 (CVE-2023-28176)\n\n* Mozilla: Potential out-of-bounds when accessing throttled streams (CVE-2023-25752)\n\n* Mozilla: Invalid downcast in Worklets (CVE-2023-28162)\n\n* Mozilla: URL being dragged from a removed cross-origin iframe into the same tab triggered navigation (CVE-2023-28164)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2178458", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2178458", "description": ""}, {"ticket": "2178460", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2178460", "description": ""}, {"ticket": "2178466", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2178466", "description": ""}, {"ticket": "2178470", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2178470", "description": ""}, {"ticket": "2178472", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2178472", "description": ""}], "cves": [{"name": "CVE-2023-25751","sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-25751", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-94"}, {"name": "CVE-2023-25752", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-25752", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-125"}, {"name": "CVE-2023-28162", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-28162", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-704"}, {"name": "CVE-2023-28164", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-28164", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-829"}, {"name": "CVE-2023-28176", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-28176", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-120"}], "references": [], "publishedAt": "2023-04-06T15:53:36.002725Z", "rpms": {"Rocky Linux 9": {"nvras": ["firefox-0:102.9.0-3.el9_1.aarch64.rpm", "firefox-0:102.9.0-3.el9_1.ppc64le.rpm", "firefox-0:102.9.0-3.el9_1.s390x.rpm", "firefox-0:102.9.0-3.el9_1.src.rpm", "firefox-0:102.9.0-3.el9_1.x86_64.rpm", "firefox-debuginfo-0:102.9.0-3.el9_1.aarch64.rpm", "firefox-debuginfo-0:102.9.0-3.el9_1.ppc64le.rpm", "firefox-debuginfo-0:102.9.0-3.el9_1.s390x.rpm", "firefox-debuginfo-0:102.9.0-3.el9_1.x86_64.rpm", "firefox-debugsource-0:102.9.0-3.el9_1.aarch64.rpm", "firefox-debugsource-0:102.9.0-3.el9_1.ppc64le.rpm", "firefox-debugsource-0:102.9.0-3.el9_1.s390x.rpm", "firefox-debugsource-0:102.9.0-3.el9_1.x86_64.rpm", "firefox-x11-0:102.9.0-3.el9_1.aarch64.rpm", "firefox-x11-0:102.9.0-3.el9_1.ppc64le.rpm", "firefox-x11-0:102.9.0-3.el9_1.s390x.rpm", "firefox-x11-0:102.9.0-3.el9_1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}.Crucial security patch for Firefox on Rocky Linux 9 tackles multiple major vulnerabilities. Stay informed for comprehensive insights on essential updates.. Firefox Security Updates, Rocky Linux Patches, Browser Security Fixes, Important Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 06, 2023 Important Rocky Linux
100

SUSE 15-SP1: 2021:0245-1 Important Memory and Leak Fix for Thunderbird

An update that fixes 6 vulnerabilities is now available. . SUSE Security Update: Security update for MozillaThunderbird ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0245-1 Rating: important References: #1181414 Cross-References: CVE-2020-15685 CVE-2020-26976 CVE-2021-23953 CVE-2021-23954 CVE-2021-23960 CVE-2021-23964 Affected Products: SUSE Linux Enterprise Workstation Extension 15-SP1 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for MozillaThunderbird fixes the following issues: - Mozilla Thunderbird was updated to 78.7.0 ESR (MFSA 2021-05, bsc#1181414) * CVE-2021-23953: Fixed a Cross-origin information leakage via redirected PDF requests * CVE-2021-23954: Fixed a type confusion when using logical assignment operators in JavaScript switch statements * CVE-2020-26976: Fixed an issue where HTTPS pages could have been intercepted by a registered service worker when they should not have been * CVE-2021-23960: Fixed a use-after-poison for incorrectly redeclared JavaScript variables during GC * CVE-2021-23964: Fixed Memory safety bugs * CVE-2020-15685: Fixed an IMAP Response Injection when using STARTTLS Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15-SP1: zypper in -t patch SUSE-SLE-Product-WE-15-SP1-2021-245=1 Package List: - SUSE Linux Enterprise Workstation Extension 15-SP1 (x86_64): MozillaThunderbird-78.7.0-3.119.1 MozillaThunderbird-debuginfo-78.7.0-3.119.1 MozillaThunderbird-debugsource-78.7.0-3.119.1 MozillaThunderbird-translations-common-78.7.0-3.119.1 MozillaThunderbird-translations-other-78.7.0-3.119.1 References: https://www.suse.com/security/cve/CVE-2020-15685.html https://www.suse.com/security/cve/CVE-2020-26976.html https://www.suse.com/security/cve/CVE-2021-23953.html https://www.suse.com/security/cve/CVE-2021-23954.html https://www.suse.com/security/cve/CVE-2021-23960.html https://www.suse.com/security/cve/CVE-2021-23964.html https://bugzilla.suse.com/1181414 . Important patch for MozillaThunderbird resolves various vulnerabilities, including information exposure and memory flaws.. MozillaThunderbird Update,SUSE Security Advisory,Security Issues Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 29, 2021 Important SuSE
202

openSUSE Leap 15.1: 2020:2325-1 Critical: MozillaFirefox Memory Issues

An update that fixes 8 vulnerabilities is now available. . openSUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:2325-1 Rating: critical References: #1180039 Cross-References: CVE-2020-16042 CVE-2020-26971 CVE-2020-26973 CVE-2020-26974 CVE-2020-26978 CVE-2020-35111 CVE-2020-35112 CVE-2020-35113 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes 8 vulnerabilities is now available. Description: This update for MozillaFirefox fixes the following issues: - Firefox Extended Support Release 78.6.0 ESR * Fixed: Various stability, functionality, and security fixes MFSA 2020-55 (bsc#1180039) * CVE-2020-16042 (bmo#1679003) Operations on a BigInt could have caused uninitialized memory to be exposed * CVE-2020-26971 (bmo#1663466) Heap buffer overflow in WebGL * CVE-2020-26973 (bmo#1680084) CSS Sanitizer performed incorrect sanitization * CVE-2020-26974 (bmo#1681022) Incorrect cast of StyleGenericFlexBasis resulted in a heap use-after-free * CVE-2020-26978 (bmo#1677047) Internal network hosts could have been probed by a malicious webpage * CVE-2020-35111 (bmo#1657916) The proxy.onRequest API did not catch view-source URLs * CVE-2020-35112 (bmo#1661365) Opening an extension-less download may have inadvertently launched an executable instead * CVE-2020-35113 (bmo#1664831, bmo#1673589) Memory safety bugs fixed in Firefox 84 and Firefox ESR 78.6 This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-2325=1 Package List: - openSUSE Leap 15.1 (x86_64): MozillaFirefox-78.6.0-lp151.2.82.1 MozillaFirefox-branding-upstream-78.6.0-lp151.2.82.1 MozillaFirefox-buildsymbols-78.6.0-lp151.2.82.1 MozillaFirefox-debuginfo-78.6.0-lp151.2.82.1 MozillaFirefox-debugsource-78.6.0-lp151.2.82.1 MozillaFirefox-devel-78.6.0-lp151.2.82.1 MozillaFirefox-translations-common-78.6.0-lp151.2.82.1 MozillaFirefox-translations-other-78.6.0-lp151.2.82.1 References: https://www.suse.com/security/cve/CVE-2020-16042.html https://www.suse.com/security/cve/CVE-2020-26971.html https://www.suse.com/security/cve/CVE-2020-26973.html https://www.suse.com/security/cve/CVE-2020-26974.html https://www.suse.com/security/cve/CVE-2020-26978.html https://www.suse.com/security/cve/CVE-2020-35111.html https://www.suse.com/security/cve/CVE-2020-35112.html https://www.suse.com/security/cve/CVE-2020-35113.html https://bugzilla.suse.com/1180039 _______________________________________________ openSUSE Security Announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe, email This email address is being protected from spambots. You need JavaScript enabled to view it. List Netiquette: https://en.opensuse.org/openSUSE:Mailing_list_netiquette List Archives: . Important patch for openSUSE released to address various vulnerabilities in MozillaFirefox, enhancing both security and performance.. MozillaFirefox Update, Critical Patch, Heap Overflow Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 25, 2020 Critical OpenSUSE
100

SUSE: 2020:3021-1 Important Update For MozillaFirefox Security Issues

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3021-1 Rating: important References: #1176756 #1177872 Cross-References: CVE-2020-15683 CVE-2020-15969 Affected Products: SUSE Linux Enterprise Module for Desktop Applications 15-SP2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for MozillaFirefox fixes the following issues: - Firefox Extended Support Release 78.4.0 ESR * Fixed: Various stability, functionality, and security fixes MFSA 2020-46 (bsc#1177872, bsc#1176756) * CVE-2020-15969 Use-after-free in usersctp * CVE-2020-15683 Memory safety bugs fixed in Firefox 82 and Firefox ESR 78.4 * Fixed: Fixed legacy preferences not being properly applied when set via GPO Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Desktop Applications 15-SP2: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP2-2020-3021=1 Package List: - SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (aarch64 ppc64le s390x x86_64): MozillaFirefox-78.4.0-8.11.2 MozillaFirefox-debuginfo-78.4.0-8.11.2 MozillaFirefox-debugsource-78.4.0-8.11.2 MozillaFirefox-devel-78.4.0-8.11.2 MozillaFirefox-translations-common-78.4.0-8.11.2 MozillaFirefox-translations-other-78.4.0-8.11.2 References: https://www.suse.com/security/cve/CVE-2020-15683.html https://www.suse.com/security/cve/CVE-2020-15969.html https://bugzilla.suse.com/1176756 https://bugzilla.suse.com/1177872 .Fedora Security Patch: Update resolves performance glitches and reliability concerns in GoogleChrome.. MozillaFirefox Update, SUSE Linux Security, Memory Bugs Fix, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 23, 2020 Important SuSE
200

SciLinux: SLSA-2020-0574-1 Important: Thunderbird Crash Fixes and Issues

Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800) Mozilla: Out-of-bounds read when processing certain email messages (CVE-2020-6793) Mozilla: Setting a master password post-Thunderbird 52 does not delete unencrypted previously stored passwords (CVE-2020-6794) Mozilla: Crash processing S/MIME messages with multiple signatures (CVE-2020-6795) Mozilla: Incorrect p [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2020:0574-1 Issue Date: 2020-02-24 CVE Numbers: None -- Security Fix(es): Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800) Mozilla: Out-of-bounds read when processing certain email messages (CVE-2020-6793) Mozilla: Setting a master password post-Thunderbird 52 does not delete unencrypted previously stored passwords (CVE-2020-6794) Mozilla: Crash processing S/MIME messages with multiple signatures (CVE-2020-6795) Mozilla: Incorrect parsing of template tag could result in JavaScript injection (CVE-2020-6798) Mozilla: Message ID calculation was based on uninitialized data (CVE-2020-6792) -- SL6 x86_64 thunderbird-68.5.0-1.el6_10.x86_64.rpm thunderbird-debuginfo-68.5.0-1.el6_10.x86_64.rpm i386 thunderbird-68.5.0-1.el6_10.i686.rpm thunderbird-debuginfo-68.5.0-1.el6_10.i686.rpm - Scientific Linux Development Team . Scientists must immediately apply the security update for Thunderbird to fix critical email processing bugs on SL6.. Mozilla, Thunderbird, Memory Safety, Email Security, SL6. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 25, 2020 Important Scientific Linux
202

openSUSE: 2020:0231-1 Important: MozillaThunderbird Memory Bugs Fixed

An update that fixes 7 vulnerabilities is now available.. openSUSE Security Update: Security update for MozillaThunderbird ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0231-1 Rating: important References: #1162777 #1163368 Cross-References: CVE-2020-6792 CVE-2020-6793 CVE-2020-6794 CVE-2020-6795 CVE-2020-6797 CVE-2020-6798 CVE-2020-6800 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: This update for MozillaThunderbird fixes the following issues: - Mozilla Thunderbird 68.5 (bsc#1162777) MFSA 2020-07 (bsc#1163368) * CVE-2020-6793 (bmo#1608539) Out-of-bounds read when processing certain email messages * CVE-2020-6794 (bmo#1606619) Setting a master password post-Thunderbird 52 does not delete unencrypted previously stored passwords * CVE-2020-6795 (bmo#1611105) Crash processing S/MIME messages with multiple signatures * CVE-2020-6797 (bmo#1596668) Extensions granted downloads.open permission could open arbitrary applications on Mac OSX * CVE-2020-6798 (bmo#1602944) Incorrect parsing of template tag could result in JavaScript injection * CVE-2020-6792 (bmo#1609607) Message ID calculcation was based on uninitialized data * CVE-2020-6800 (bmo#1595786, bmo#1596706, bmo#1598543, bmo#1604851, bmo#1605777, bmo#1608580, bmo#1608785) Memory safety bugs fixed in Thunderbird 68.5 * new: Support for Client Identity IMAP/SMTP Service Extension (bmo#1532388) * new: Support for OAuth 2.0 authentication for POP3 accounts (bmo#1538409) * fixed: Status area goes blank during account setup (bmo#1593122) * fixed: Calendar: Could not remove color for default categories (bmo#1584853) * fixed:Calendar: Prevent calendar component loading multiple times (bmo#1606375) * fixed: Calendar: Today pane did not retain width between sessions (bmo#1610207) * unresolved: When upgrading from Thunderbird version 60 to version 68, add-ons are not automatically updated during the upgrade process. They will however be updated during the add- on update check. It is of course possible to reinstall compatible add-ons via the Add-ons Manager or via addons.thunderbird.net. (bmo#1574183) * changed: Calendar: Task and Event tree colours adjusted for the dark theme (bmo#1608344) * fixed: Retrieval of S/MIME certificates from LDAP failed (bmo#1604773) * fixed: Address-parsing crash on some IMAP servers when preference mail.imap.use_envelope_cmd was set (bmo#1609690) * fixed: Incorrect forwarding of HTML messages caused SMTP servers to respond with a timeout (bmo#1222046) * fixed: Calendar: Various parts of the calendar UI stopped working when a second Thunderbird window opened (bmo#1608407) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-231=1 Package List: - openSUSE Leap 15.1 (x86_64): MozillaThunderbird-68.5.0-lp151.2.25.1 MozillaThunderbird-debuginfo-68.5.0-lp151.2.25.1 MozillaThunderbird-debugsource-68.5.0-lp151.2.25.1 MozillaThunderbird-translations-common-68.5.0-lp151.2.25.1 MozillaThunderbird-translations-other-68.5.0-lp151.2.25.1 References: https://www.suse.com/security/cve/CVE-2020-6792.html https://www.suse.com/security/cve/CVE-2020-6793.html https://www.suse.com/security/cve/CVE-2020-6794.html https://www.suse.com/security/cve/CVE-2020-6795.html https://www.suse.com/security/cve/CVE-2020-6797.html https://www.suse.com/security/cve/CVE-2020-6798.html https://www.suse.com/security/cve/CVE-2020-6800.html https://bugzilla.suse.com/1162777 https://bugzilla.suse.com/1163368 -- . The latest update for Mozilla Thunderbird addresses several security concerns, notably enhancing memory protection and fixing authentication flaws.. openSUSE, MozillaThunderbird, security update, memory safety, authentication. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 18, 2020 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200