openSUSE-SU-2016:1769-1
Dashboard / Vulnerabilities / openSUSE-SU-2016:1769-1
openSUSE-SU-2016:1769-1
Summary: Security update for Mozilla Thunderbird
Details: This update contains Mozilla Thunderbird 45.2. (boo#983549) It fixes security issues mostly affecting the e-mail program when used in a browser context, such as viewing a web page or HTMl formatted e-mail. The following vulnerabilities were fixed: - CVE-2016-2818, CVE-2016-2815: Memory safety bugs (boo#983549, MFSA2016-49) Contains the following security fixes from the 45.1 release: (boo#977333) - CVE-2016-2806, CVE-2016-2807: Miscellaneous memory safety hazards (boo#977375, boo#977376, MFSA 2016-39) Contains the following security fixes from the 45.0 release: (boo#969894) - CVE-2016-1952, CVE-2016-1953: Miscellaneous memory safety hazards (MFSA 2016-16) - CVE-2016-1954: Local file overwriting and potential privilege escalation through CSP reports (MFSA 2016-17) - CVE-2016-1955: CSP reports fail to strip location information for embedded iframe pages (MFSA 2016-18) - CVE-2016-1956: Linux video memory DOS with Intel drivers (MFSA 2016-19) - CVE-2016-1957: Memory leak in libstagefright when deleting an array during MP4 processing (MFSA 2016-20) - CVE-2016-1960: Use-after-free in HTML5 string parser (MFSA 2016-23) - CVE-2016-1961: Use-after-free in SetBody (MFSA 2016-24) - CVE-2016-1964: Use-after-free during XML transformations (MFSA 2016-27) - CVE-2016-1974: Out-of-bounds read in HTML parser following a failed allocation (MFSA 2016-34) The graphite font shaping library was disabled, addressing the following font vulnerabilities: - MFSA 2016-37/CVE-2016-1977/CVE-2016-2790/CVE-2016-2791/ CVE-2016-2792/CVE-2016-2793/CVE-2016-2794/CVE-2016-2795/ CVE-2016-2796/CVE-2016-2797/CVE-2016-2798/CVE-2016-2799/ CVE-2016-2800/CVE-2016-2801/CVE-2016-2802 The following tracked packaging changes are included: - fix build issues with gcc/binutils combination used in Leap 42.2 (boo#984637) - gcc6 fixes (boo#986162) - running on 48bit va aarch64 (boo#984126)
References: https://lists.opensuse.org/archives/list/[email protected]/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5, https://bugzilla.suse.com/969894, https://bugzilla.suse.com/977333, https://bugzilla.suse.com/977375, https://bugzilla.suse.com/977376, https://bugzilla.suse.com/983549, https://bugzilla.suse.com/984126, https://bugzilla.suse.com/984637, https://bugzilla.suse.com/986162, https://www.suse.com/security/cve/CVE-2016-1952, https://www.suse.com/security/cve/CVE-2016-1953, https://www.suse.com/security/cve/CVE-2016-1954, https://www.suse.com/security/cve/CVE-2016-1955, https://www.suse.com/security/cve/CVE-2016-1956, https://www.suse.com/security/cve/CVE-2016-1957, https://www.suse.com/security/cve/CVE-2016-1960, https://www.suse.com/security/cve/CVE-2016-1961, https://www.suse.com/security/cve/CVE-2016-1964, https://www.suse.com/security/cve/CVE-2016-1974, https://www.suse.com/security/cve/CVE-2016-1977, https://www.suse.com/security/cve/CVE-2016-2790, https://www.suse.com/security/cve/CVE-2016-2791, https://www.suse.com/security/cve/CVE-2016-2792, https://www.suse.com/security/cve/CVE-2016-2793, https://www.suse.com/security/cve/CVE-2016-2794, https://www.suse.com/security/cve/CVE-2016-2795, https://www.suse.com/security/cve/CVE-2016-2796, https://www.suse.com/security/cve/CVE-2016-2797, https://www.suse.com/security/cve/CVE-2016-2798, https://www.suse.com/security/cve/CVE-2016-2799, https://www.suse.com/security/cve/CVE-2016-2800, https://www.suse.com/security/cve/CVE-2016-2801, https://www.suse.com/security/cve/CVE-2016-2802, https://www.suse.com/security/cve/CVE-2016-2806, https://www.suse.com/security/cve/CVE-2016-2807, https://www.suse.com/security/cve/CVE-2016-2815, https://www.suse.com/security/cve/CVE-2016-2818
Affected packages
Package
Name: MozillaThunderbird
Purl: pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Package%20Hub%2012
Affected ranges
Type: ECOSYSTEM
Events:
