openSUSE-SU-2017:3433-1
Dashboard / Vulnerabilities / openSUSE-SU-2017:3433-1
openSUSE-SU-2017:3433-1
Summary: Security update for Mozilla Thunderbird
Details: This update for Mozilla Thunderbird to version 52.5.2 fixes the following vulnerabilities: - CVE-2017-7846: JavaScript Execution via RSS in mailbox:// origin (bsc#1074043) - CVE-2017-7847: Local path string can be leaked from RSS feed (bsc#1074044) - CVE-2017-7848: RSS Feed vulnerable to new line Injection (bsc#1074045) - CVE-2017-7829: From address with encoded null character is cut off in message header display (bsc#1074046)
References: https://lists.opensuse.org/archives/list/[email protected]/thread/Y37ZBDTQYH6U74CLMVTFTTZQHZYSKJPC/#Y37ZBDTQYH6U74CLMVTFTTZQHZYSKJPC, https://bugzilla.suse.com/1074043, https://bugzilla.suse.com/1074044, https://bugzilla.suse.com/1074045, https://bugzilla.suse.com/1074046, https://www.suse.com/security/cve/CVE-2017-7829, https://www.suse.com/security/cve/CVE-2017-7846, https://www.suse.com/security/cve/CVE-2017-7847, https://www.suse.com/security/cve/CVE-2017-7848
Affected packages
Package
Name: MozillaThunderbird
Purl: pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Package%20Hub%2012
Affected ranges
Type: ECOSYSTEM
Events:
