openSUSE-SU-2021:2458-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:2458-1
openSUSE-SU-2021:2458-1
Summary: Security update for MozillaThunderbird
Details: This update for MozillaThunderbird fixes the following issues: Mozilla Thunderbird 78.12 * fixed: Sending an email containing HTML links with spaces in the URL sometimes resulted in broken links * fixed: Folder Pane display theme fixes for macOS * fixed: Chat account settings did not always save as expected * fixed: RSS feed subscriptions sometimes lost * fixed: Calendar: A parsing error for alarm triggers of type 'DURATION' caused sync problems for some users * fixed: Various security fixes MFSA 2021-30 (bsc#1188275) * CVE-2021-29969: IMAP server responses sent by a MITM prior to STARTTLS could be processed * CVE-2021-29970: Use-after-free in accessibility features of a document * CVE-2021-30547: Out of bounds write in ANGLE * CVE-2021-29976: Memory safety bugs fixed in Thunderbird 78.12
References: https://lists.opensuse.org/archives/list/[email protected]/thread/AQOPHIOAWOQQLB7SCESJM5UI67QUVORM/, https://bugzilla.suse.com/1188275, https://www.suse.com/security/cve/CVE-2021-29969, https://www.suse.com/security/cve/CVE-2021-29970, https://www.suse.com/security/cve/CVE-2021-29976, https://www.suse.com/security/cve/CVE-2021-30547
Affected packages
Package
Name: MozillaThunderbird
Purl: pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
