openSUSE-SU-2017:1579-1

    Dashboard / Vulnerabilities / openSUSE-SU-2017:1579-1

    openSUSE-SU-2017:1579-1

    Published: 16 Jun 2017Last Modified: 4 Feb 2026

    Summary: Security update for Mozilla Thunderbird

    Details: This update to Thunderbird 52.2 fixes security issues and bugs. The following vulnerabilities were fixed: * CVE-2017-5472: Use-after-free using destroyed node when regenerating trees * CVE-2017-7749: Use-after-free during docshell reloading * CVE-2017-7750: Use-after-free with track elements * CVE-2017-7751: Use-after-free with content viewer listeners * CVE-2017-7752: Use-after-free with IME input * CVE-2017-7754: Out-of-bounds read in WebGL with ImageInfo object * CVE-2017-7756: Use-after-free and use-after-scope logging XHR header errors * CVE-2017-7757: Use-after-free in IndexedDB * CVE-2017-7778, CVE-2017-7778, CVE-2017-7771, CVE-2017-7772, CVE-2017-7773, CVE-2017-7774, CVE-2017-7775, CVE-2017-7776, CVE-2017-7777: Vulnerabilities in the Graphite 2 library * CVE-2017-7758: Out-of-bounds read in Opus encoder * CVE-2017-7764: Domain spoofing with combination of Canadian Syllabics and other unicode blocks * CVE-2017-5470: Memory safety bugs fixed in Firefox 54 and Firefox ESR 52.2 Mozilla Thunderbird now requires NSS 3.28.5. The following bugs were fixed: * Embedded images not shown in email received from Hotmail/Outlook webmailer * Detection of non-ASCII font names in font selector * Attachment not forwarded correctly under certain circumstances * Multiple requests for master password when GMail OAuth2 is enabled * Large number of blank pages being printed under certain circumstances when invalid preferences were present * Messages sent via the Simple MAPI interface are forced to HTML * Calendar: Invitations can't be printed * Mailing list (group) not accessible from macOS or Outlook address book * Clicking on links with references/anchors where target doesn't exist in the message not opening in external browser

    References: , https://bugzilla.suse.com/1040105, https://bugzilla.suse.com/1042090, https://bugzilla.suse.com/1043960, https://bugzilla.suse.com/1273265, https://bugzilla.suse.com/1355039, https://bugzilla.suse.com/1356558, https://bugzilla.suse.com/1356824, https://bugzilla.suse.com/1357090, https://bugzilla.suse.com/1359547, https://bugzilla.suse.com/1360309, https://bugzilla.suse.com/1363396, https://bugzilla.suse.com/1364283, https://bugzilla.suse.com/1365602, https://bugzilla.suse.com/1366595, https://bugzilla.suse.com/1368490, https://www.suse.com/security/cve/CVE-2017-5470, https://www.suse.com/security/cve/CVE-2017-5472, https://www.suse.com/security/cve/CVE-2017-7749, https://www.suse.com/security/cve/CVE-2017-7750, https://www.suse.com/security/cve/CVE-2017-7751, https://www.suse.com/security/cve/CVE-2017-7752, https://www.suse.com/security/cve/CVE-2017-7754, https://www.suse.com/security/cve/CVE-2017-7756, https://www.suse.com/security/cve/CVE-2017-7757, https://www.suse.com/security/cve/CVE-2017-7758, https://www.suse.com/security/cve/CVE-2017-7763, https://www.suse.com/security/cve/CVE-2017-7764, https://www.suse.com/security/cve/CVE-2017-7765, https://www.suse.com/security/cve/CVE-2017-7771, https://www.suse.com/security/cve/CVE-2017-7772, https://www.suse.com/security/cve/CVE-2017-7773, https://www.suse.com/security/cve/CVE-2017-7774, https://www.suse.com/security/cve/CVE-2017-7775, https://www.suse.com/security/cve/CVE-2017-7776, https://www.suse.com/security/cve/CVE-2017-7777, https://www.suse.com/security/cve/CVE-2017-7778

    Affected packages

    Package

    Name: MozillaThunderbird

    Purl: pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Package%20Hub%2012

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -52.2-36.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High