Mailinglist Archive: opensuse-updates (180 mails)

< Previous Next >
openSUSE-SU-2017:0026-1: moderate: Security update for MozillaThunderbird
openSUSE Security Update: Security update for MozillaThunderbird
______________________________________________________________________________

Announcement ID: openSUSE-SU-2017:0026-1
Rating: moderate
References: #1015422
Cross-References: CVE-2016-9893 CVE-2016-9895 CVE-2016-9897
CVE-2016-9898 CVE-2016-9899 CVE-2016-9900
CVE-2016-9904 CVE-2016-9905
Affected Products:
openSUSE 13.1
______________________________________________________________________________

An update that fixes 8 vulnerabilities is now available.

Description:

This update to Mozilla Thunderbird 45.6.0 fixes security issues and
bugs.

In general, these flaws cannot be exploited through email in
Thunderbird because scripting is disabled when reading mail, but are
potentially risks in browser or browser-like contexts.

The following vulnerabilities were fixed: (boo#1015422)

- CVE-2016-9899: Use-after-free while manipulating DOM events and audio
elements
- CVE-2016-9895: CSP bypass using marquee tag
- CVE-2016-9897: Memory corruption in libGLES
- CVE-2016-9898: Use-after-free in Editor while manipulating DOM
subtrees
- CVE-2016-9900: Restricted external resources can be loaded by SVG
images through data URLs
- CVE-2016-9904: Cross-origin information leak in shared atoms
- CVE-2016-9905: Crash in EnumerateSubDocuments
- CVE-2016-9893: Memory safety bugs fixed in Thunderbird 45.6

The following bugs were fixed:

- The system integration dialog was shown every time when starting
Thunderbird


Patch Instructions:

To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

- openSUSE 13.1:

zypper in -t patch 2017-15=1

To bring your system up-to-date, use "zypper patch".


Package List:

- openSUSE 13.1 (i586 x86_64):

MozillaThunderbird-45.6.0-70.95.1
MozillaThunderbird-buildsymbols-45.6.0-70.95.1
MozillaThunderbird-debuginfo-45.6.0-70.95.1
MozillaThunderbird-debugsource-45.6.0-70.95.1
MozillaThunderbird-devel-45.6.0-70.95.1
MozillaThunderbird-translations-common-45.6.0-70.95.1
MozillaThunderbird-translations-other-45.6.0-70.95.1


References:

https://www.suse.com/security/cve/CVE-2016-9893.html
https://www.suse.com/security/cve/CVE-2016-9895.html
https://www.suse.com/security/cve/CVE-2016-9897.html
https://www.suse.com/security/cve/CVE-2016-9898.html
https://www.suse.com/security/cve/CVE-2016-9899.html
https://www.suse.com/security/cve/CVE-2016-9900.html
https://www.suse.com/security/cve/CVE-2016-9904.html
https://www.suse.com/security/cve/CVE-2016-9905.html
https://bugzilla.suse.com/1015422


< Previous Next >
This Thread
  • No further messages