[openSUSE-SU-2020:0094-1] Security update for MozillaThunderbird

Severity Important
Affected Packages 3
CVEs 7

Security update for MozillaThunderbird

This update for MozillaThunderbird to version 68.4.1 fixes the following issues:

Security issues fixed:

  • CVE-2019-17026: IonMonkey type confusion with StoreElementHole and FallibleStoreElement
  • CVE-2019-17016: Bypass of @namespace CSS sanitization during pasting
  • CVE-2019-17017: Type Confusion in XPCVariant.cpp
  • CVE-2019-17022: CSS sanitization does not escape HTML tags
  • CVE-2019-17024: multiple Memory safety bugs fixed

Non-security issues fixed:

  • Various improvements when setting up an account for a Microsoft Exchange server. For example better detection for Office 365 accounts.

This update was imported from the SUSE:SLE-15:Update update project.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/MozillaThunderbird?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaThunderbird < 68.4.1-lp151.2.22.2 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaThunderbird-translations-other?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaThunderbird-translations-other < 68.4.1-lp151.2.22.2 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaThunderbird-translations-common?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaThunderbird-translations-common < 68.4.1-lp151.2.22.2 opensuse-leap-15.1 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date