SUSE-SU-2018:3769-1
Dashboard / Vulnerabilities / SUSE-SU-2018:3769-1
SUSE-SU-2018:3769-1
Summary: Security update for MozillaThunderbird
Details: This update for MozillaThunderbird fixes the following issues: Thunderbird 63 ESR was updated to version 60.3.0 to fix the following issues (bsc#1112852): Security issues fixed (MFSA 2018-28): - CVE-2018-12389: Fixed memory safety bugs. - CVE-2018-12390: Fixed memory safety bugs. - CVE-2018-12391: Fixed HTTP Live Stream audio data is accessible cross-origin. - CVE-2018-12392: Fixed crash with nested event loops. - CVE-2018-12393: Fixed integer overflow during Unicode conversion while loading JavaScript. Non-security issues fixed: - various theme fixes - Shift+PageUp/PageDown in Write window - Gloda attachment filtering - Mailing list address auto-complete enter/return handling - Thunderbird hung if HTML signature references non-existent image - Filters not working for headers that appear more than once - Update _constraints for armv6/7 - Add memory-constraints to avoid OOM errors
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183769-1/, https://bugzilla.suse.com/1112852, https://www.suse.com/security/cve/CVE-2018-12389, https://www.suse.com/security/cve/CVE-2018-12390, https://www.suse.com/security/cve/CVE-2018-12391, https://www.suse.com/security/cve/CVE-2018-12392, https://www.suse.com/security/cve/CVE-2018-12393
Affected packages
Package
Name: MozillaThunderbird
Purl: pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015
Affected ranges
Type: ECOSYSTEM
Events:
