[openSUSE-SU-2018:0257-1] Security update for MozillaThunderbird
Severity
Important
Affected Packages
5
CVEs
10
Security update for MozillaThunderbird
This update for MozillaThunderbird to version 52.6 fixes several issues.
These security issues were fixed:
- CVE-2018-5095: Integer overflow in Skia library during edge builder allocation (bsc#1077291).
- CVE-2018-5096: Use-after-free while editing form elements (bsc#1077291).
- CVE-2018-5097: Use-after-free when source document is manipulated during XSLT (bsc#1077291).
- CVE-2018-5098: Use-after-free while manipulating form input elements (bsc#1077291).
- CVE-2018-5099: Use-after-free with widget listener (bsc#1077291).
- CVE-2018-5102: Use-after-free in HTML media elements (bsc#1077291).
- CVE-2018-5103: Use-after-free during mouse event handling (bsc#1077291).
- CVE-2018-5104: Use-after-free during font face manipulation (bsc#1077291).
- CVE-2018-5117: URL spoofing with right-to-left text aligned left-to-right (bsc#1077291).
- CVE-2018-5089: Various memory safety bugs (bsc#1077291).
These security issues were fixed:
- Searching message bodies of messages in local folders, including filter and quick filter operations, not working reliably: Content not found in base64-encode message parts, non-ASCII text not found and false positives found.
- Defective messages (without at least one expected header) not shown in IMAP folders but shown on mobile devices
- Calendar: Unintended task deletion if numlock is enabled
- ID
- openSUSE-SU-2018:0257-1
- Severity
- important
- URL
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IQKYFID4LB22UT3U2EOJ242RTGFRORJJ/#IQKYFID4LB22UT3U2EOJ242RTGFRORJJ
- Published
-
2018-01-27T21:50:06
(6 years ago) - Modified
-
2018-01-27T21:50:06
(6 years ago) - Rights
- Copyright 2024 SUSE LLC. All rights reserved.
- Other Advisories
-
- ALPINE:CVE-2018-5089
- ALPINE:CVE-2018-5095
- ALPINE:CVE-2018-5096
- ALPINE:CVE-2018-5097
- ALPINE:CVE-2018-5098
- ALPINE:CVE-2018-5099
- ALPINE:CVE-2018-5102
- ALPINE:CVE-2018-5103
- ALPINE:CVE-2018-5104
- ALPINE:CVE-2018-5117
- DSA-4096-1
- DSA-4102-1
- ELSA-2018-0122
- ELSA-2018-0262
- FREEBSD:5044BD23-08CB-11E8-B08F-00012E582166
- FREEBSD:A891C5B4-3D7A-4DE9-9C71-EEF3FD698C77
- GLSA-201802-03
- GLSA-201803-14
- MFSA-2018-02
- MFSA-2018-03
- MFSA-2018-04
- openSUSE-SU-2018:0256-1
- RHSA-2018:0122
- RHSA-2018:0262
- SUSE-SU-2018:0361-1
- SUSE-SU-2018:0374-1
- USN-3529-1
- USN-3544-1
- USN-3688-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/opensuse/MozillaThunderbird?arch=x86_64&distro=opensuse-12&repo=suse-package-hub | opensuse | MozillaThunderbird | < 52.6-54.1 | opensuse-12 | x86_64 | |
Affected | pkg:rpm/opensuse/MozillaThunderbird-translations-other?arch=x86_64&distro=opensuse-12&repo=suse-package-hub | opensuse | MozillaThunderbird-translations-other | < 52.6-54.1 | opensuse-12 | x86_64 | |
Affected | pkg:rpm/opensuse/MozillaThunderbird-translations-common?arch=x86_64&distro=opensuse-12&repo=suse-package-hub | opensuse | MozillaThunderbird-translations-common | < 52.6-54.1 | opensuse-12 | x86_64 | |
Affected | pkg:rpm/opensuse/MozillaThunderbird-devel?arch=x86_64&distro=opensuse-12&repo=suse-package-hub | opensuse | MozillaThunderbird-devel | < 52.6-54.1 | opensuse-12 | x86_64 | |
Affected | pkg:rpm/opensuse/MozillaThunderbird-buildsymbols?arch=x86_64&distro=opensuse-12&repo=suse-package-hub | opensuse | MozillaThunderbird-buildsymbols | < 52.6-54.1 | opensuse-12 | x86_64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |