New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] mozilla-thunderbird (SSA:2024-317-01) New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/mozilla-thunderbird-128.4.3esr-i686-1_slack15.0.txz: Upgraded. This release contains security fixes and improvements. For more information, see: https://www.thunderbird.net/en-US/thunderbird/128.4.3esr/releasenotes/ (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-thunderbird-128.4.3esr-i686-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/mozilla-thunderbird-128.4.3esr-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-thunderbird-128.4.3esr-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/mozilla-thunderbird-128.4.3esr-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: d607bc88d35fc7c704605188033b6d8f mozilla-thunderbird-128.4.3esr-i686-1_slack15.0.txz Slackware x86_64 15.0 package: fbfd88ce3c8d7843341ce45050c9bef6 mozilla-thunderbird-128.4.3esr-x86_64-1_slack15.0.txz Slackware -current package: 5a49357a837381304562eb410fdd29c3 xap/mozilla-thunderbird-128.4.3esr-i686-1.txz Slackware x86_64-current package: d2bba6ac32a8b459bbb324ce773218ed xap/mozilla-thunderbird-128.4.3esr-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg mozilla-thunderbird-128.4.3esr-i686-1_slack15.0.txz +-----+ . Recent package updates for mozilla-thunderbird address security vulnerabilities for Slackware 15.0 and the current development versions.. mozilla-thunderbird update, Slackware packages, security issues, linux patch. . Severity: Critical. LinuxSecurity.com Team
This update upgrades Thunderbird to version 60.8.0. * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2019:1777-1 Issue Date: 2019-07-15 CVE Numbers: CVE-2019-11709 CVE-2019-11711 CVE-2019-11712 CVE-2019-11713 CVE-2019-11715 CVE-2019-11717 CVE-2019-11730 CVE-2019-9811 -- This update upgrades Thunderbird to version 60.8.0. Security Fix(es): * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects (CVE-2019-11712) * Mozilla: Use-after-free with HTTP/2 cached stream (CVE-2019-11713) * Mozilla: HTML parsing error can contribute to content XSS (CVE-2019-11715) * Mozilla: Caret character improperly escaped in origins (CVE-2019-11717) * Mozilla: Same-origin policy treats all files in a directory as having the same-origin (CVE-2019-11730) -- SL6 x86_64 thunderbird-60.8.0-1.el6_10.x86_64.rpm thunderbird-debuginfo-60.8.0-1.el6_10.x86_64.rpm i386 thunderbird-60.8.0-1.el6_10.i686.rpm thunderbird-debuginfo-60.8.0-1.el6_10.i686.rpm - Scientific Linux Development Team . Firefox security patch for SL6 resolves several Mozilla vulnerabilities. Advisory ID:SLSA-2019:1778-1 Release Date: 2019-07-16.. thunderbird update, security advisory, Mozilla vulnerabilities, SL6 upgrade. . Severity:Critical. LinuxSecurity.com Team
New Firefox and Thunderbird packages are available for Slackware 10.2 and -current to fix security issues. In addition, a new Seamonkey package is available for Slackware -current to fix similar issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] firefox/thunderbird/seamonkey (SSA:2006-208-01) New Firefox and Thunderbird packages are available for Slackware 10.2 and -current to fix security issues. In addition, a new Seamonkey package is available for Slackware -current to fix similar issues. More details about the issues may be found here: https://www.mozilla.org/en-US/security/known-vulnerabilities/ https://www.mozilla.org/en-US/security/known-vulnerabilities/ https://www.mozilla.org/en-US/security/known-vulnerabilities/ Here are the details from the Slackware 10.2 ChangeLog: +--------------------------+ patches/packages/mozilla-firefox-1.5.0.5-i686-1.tgz: Upgraded to firefox-1.5.0.5. This upgrade fixes several possible security bugs. For more information, see: https://www.mozilla.org/en-US/security/known-vulnerabilities/ (* Security fix *) patches/packages/mozilla-thunderbird-1.5.0.5-i686-1.tgz: Upgraded to thunderbird-1.5.0.5. This upgrade fixes several possible security bugs. For more information, see: https://www.mozilla.org/en-US/security/known-vulnerabilities/ (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading from ftp.slackware.com. Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated packages for Slackware 10.2: Updated packages for Slackware -current: MD5signatures: +-------------+ Slackware 10.2 packages: d91f181d70476d65be1d05ef8f1243da mozilla-firefox-1.5.0.5-i686-1.tgz 2d1b7e7f83e2032bf98c7b16aee2ffe1 mozilla-thunderbird-1.5.0.5-i686-1.tgz Slackware -current packages: e1445dc156424e179ac06ba9db0b77b4 mozilla-firefox-1.5.0.5-i686-1.tgz d396d14282a52f6ee87cda9cc44a4bf6 mozilla-thunderbird-1.5.0.5-i686-1.tgz be11c23817b8b6e7b6b567626b412427 seamonkey-1.0.3-i486-1.tgz Installation instructions: +------------------------+ Upgrade the packages as root: # upgradepkg mozilla-firefox-1.5.0.5-i686-1.tgz mozilla-thunderbird-1.5.0.5-i686-1.tgz And for Slackware -current: # upgradepkg seamonkey-1.0.3-i486-1.tgz +-----+ . Updated Firefox, Thunderbird, and Seamonkey packages for Slackware fix various security issues. Essential upgrades now released.. Slackware Security Update, Firefox Upgrade, Thunderbird Patch, Seamonkey Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.