SUSE-SU-2019:2515-1

    Dashboard / Vulnerabilities / SUSE-SU-2019:2515-1

    SUSE-SU-2019:2515-1

    Published: 2 Oct 2019Last Modified: 4 Feb 2026

    Summary: Security update for MozillaThunderbird

    Details: This update for MozillaThunderbird to version 68.1.1 fixes the following issues: - CVE-2019-11709: Fixed several memory safety bugs. (bsc#1140868) - CVE-2019-11710: Fixed several memory safety bugs. (bsc#1140868) - CVE-2019-11711: Fixed a script injection within domain through inner window reuse. (bsc#1140868) - CVE-2019-11712: Fixed an insufficient validation of cross-origin POST requests within NPAPI plugins. (bsc#1140868) - CVE-2019-11713: Fixed a use-after-free with HTTP/2 cached stream. (bsc#1140868) - CVE-2019-11714: Fixed a crash in NeckoChild. (bsc#1140868) - CVE-2019-11715: Fixed an HTML parsing error that can contribute to content XSS. (bsc#1140868) - CVE-2019-11716: Fixed an enumeration issue in globalThis. (bsc#1140868) - CVE-2019-11717: Fixed an improper escaping of the caret character in origins. (bsc#1140868) - CVE-2019-11719: Fixed an out-of-bounds read when importing curve25519 private key. (bsc#1140868) - CVE-2019-11720: Fixed a character encoding XSS vulnerability. (bsc#1140868) - CVE-2019-11721: Fixed domain spoofing through unicode latin 'kra' character. (bsc#1140868) - CVE-2019-11723: Fixed a cookie leakage during add-on fetching across private browsing boundaries. (bsc#1140868) - CVE-2019-11724: Fixed a permissions issue with the retired site input.mozilla.org. (bsc#1140868) - CVE-2019-11725: Fixed a SafeBrowsing bypass through WebSockets. (bsc#1140868) - CVE-2019-11727: Fixed an insufficient validation for PKCS#1 v1.5 signatures being used with TLS 1.3. (bsc#1140868) - CVE-2019-11728: Fixed port scanning through Alt-Svc header. (bsc#1140868) - CVE-2019-11729: Fixed a segmentation fault due to empty or malformed p256-ECDH public keys. (bsc#1140868) - CVE-2019-11730: Fixed an insufficient enforcement of the same-origin policy that treats all files in a directory as having the same-origin. (bsc#1140868) - CVE-2019-11739: Fixed a Covert Content Attack on S/MIME encryption using a crafted multipart/alternative message. (bsc#1150939) - CVE-2019-11740: Fixed several memory safety bugs. (bsc#1149299) - CVE-2019-11742: Fixed a same-origin policy violation with SVG filters and canvas that enabled theft of cross-origin images. (bsc#1149303) - CVE-2019-11743: Fixed a cross-origin access issue. (bsc#1149298) - CVE-2019-11744: Fixed a XSS involving breaking out of title and textarea elements using innerHTML. (bsc#1149304) - CVE-2019-11746: Fixed a use-after-free while manipulating video. (bsc#1149297) - CVE-2019-11752: Fixed a use-after-free while extracting a key value in IndexedDB. (bsc#1149296) - CVE-2019-11755: Fixed an insufficient validation of S/MIME messages that allowed the author to be spoofed. (bsc#1152375)

    References: https://www.suse.com/support/update/announcement/2019/suse-su-20192515-1/, https://bugzilla.suse.com/1140868, https://bugzilla.suse.com/1141322, https://bugzilla.suse.com/1149296, https://bugzilla.suse.com/1149297, https://bugzilla.suse.com/1149298, https://bugzilla.suse.com/1149299, https://bugzilla.suse.com/1149303, https://bugzilla.suse.com/1149304, https://bugzilla.suse.com/1150939, https://bugzilla.suse.com/1152375, https://www.suse.com/security/cve/CVE-2019-11709, https://www.suse.com/security/cve/CVE-2019-11710, https://www.suse.com/security/cve/CVE-2019-11711, https://www.suse.com/security/cve/CVE-2019-11712, https://www.suse.com/security/cve/CVE-2019-11713, https://www.suse.com/security/cve/CVE-2019-11714, https://www.suse.com/security/cve/CVE-2019-11715, https://www.suse.com/security/cve/CVE-2019-11716, https://www.suse.com/security/cve/CVE-2019-11717, https://www.suse.com/security/cve/CVE-2019-11719, https://www.suse.com/security/cve/CVE-2019-11720, https://www.suse.com/security/cve/CVE-2019-11721, https://www.suse.com/security/cve/CVE-2019-11723, https://www.suse.com/security/cve/CVE-2019-11724, https://www.suse.com/security/cve/CVE-2019-11725, https://www.suse.com/security/cve/CVE-2019-11727, https://www.suse.com/security/cve/CVE-2019-11728, https://www.suse.com/security/cve/CVE-2019-11729, https://www.suse.com/security/cve/CVE-2019-11730, https://www.suse.com/security/cve/CVE-2019-11739, https://www.suse.com/security/cve/CVE-2019-11740, https://www.suse.com/security/cve/CVE-2019-11742, https://www.suse.com/security/cve/CVE-2019-11743, https://www.suse.com/security/cve/CVE-2019-11744, https://www.suse.com/security/cve/CVE-2019-11746, https://www.suse.com/security/cve/CVE-2019-11752, https://www.suse.com/security/cve/CVE-2019-11755

    Affected packages

    Package

    Name: MozillaThunderbird

    Purl: pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -68.1.1-3.51.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High