[openSUSE-SU-2020:0544-1] Security update for MozillaThunderbird

Severity Important
Affected Packages 3
CVEs 5

Security update for MozillaThunderbird

This update for MozillaThunderbird to version 68.7.0 fixes the following issues:

  • CVE-2020-6819: Use-after-free while running the nsDocShell destructor (boo#1168630)
  • CVE-2020-6820: Use-after-free when handling a ReadableStream (boo#1168630)
  • CVE-2020-6821: Uninitialized memory could be read when using the WebGL copyTexSubImage() (boo#1168874)
  • CVE-2020-6822: Out of bounds write in GMPDecodeData when processing large images (boo#1168874)
  • CVE-2020-6825: Memory safety bugs fixed (boo#1168874)

This update was imported from the SUSE:SLE-15:Update update project.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/MozillaThunderbird?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaThunderbird < 68.7.0-lp151.2.35.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaThunderbird-translations-other?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaThunderbird-translations-other < 68.7.0-lp151.2.35.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaThunderbird-translations-common?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaThunderbird-translations-common < 68.7.0-lp151.2.35.1 opensuse-leap-15.1 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...