[openSUSE-SU-2020:1392-1] Security update for MozillaThunderbird
Severity
Important
Affected Packages
3
CVEs
3
Security update for MozillaThunderbird
This update for MozillaThunderbird fixes the following issues:
Mozilla Thunderbird was updated to 68.12 (bsc#1175686)
CVE-2020-15663: Downgrade attack on the Mozilla Maintenance Service could
have resulted in escalation of privilegeCVE-2020-15664: Attacker-induced prompt for extension installation
CVE-2020-15669: Use-After-Free when aborting an operation
This update was imported from the SUSE:SLE-15:Update update project.
Package | Affected Version |
---|---|
pkg:rpm/opensuse/MozillaThunderbird?arch=x86_64&distro=opensuse-leap-15.2 | < 68.12.0-lp152.2.10.1 |
pkg:rpm/opensuse/MozillaThunderbird-translations-other?arch=x86_64&distro=opensuse-leap-15.2 | < 68.12.0-lp152.2.10.1 |
pkg:rpm/opensuse/MozillaThunderbird-translations-common?arch=x86_64&distro=opensuse-leap-15.2 | < 68.12.0-lp152.2.10.1 |
- ID
- openSUSE-SU-2020:1392-1
- Severity
- important
- URL
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JNYOBI47YQLW5EKAMJETBNNXHGSR2TYF/
- Published
-
2020-09-08T18:24:18
(4 years ago) - Modified
-
2020-09-08T18:24:18
(4 years ago) - Rights
- Copyright 2024 SUSE LLC. All rights reserved.
- Other Advisories
-
- ALAS2-2020-1496
- ALPINE:CVE-2020-15663
- ALPINE:CVE-2020-15664
- DSA-4749-1
- DSA-4754-1
- ELSA-2020-3556
- ELSA-2020-3557
- ELSA-2020-3558
- ELSA-2020-3631
- ELSA-2020-3634
- ELSA-2020-3643
- GLSA-202008-16
- MFSA-2020-36
- MFSA-2020-37
- MFSA-2020-38
- MFSA-2020-39
- MFSA-2020-40
- MFSA-2020-41
- openSUSE-SU-2020:1383-1
- openSUSE-SU-2020:1384-1
- openSUSE-SU-2020:1391-1
- RHSA-2020:3556
- RHSA-2020:3557
- RHSA-2020:3558
- RHSA-2020:3631
- RHSA-2020:3634
- RHSA-2020:3643
- SSA:2020-256-01
- SUSE-SU-2020:2544-1
- SUSE-SU-2020:2552-1
- SUSE-SU-2020:2563-1
- SUSE-SU-2020:2749-1
- USN-4474-1
Source | # ID | Name | URL |
---|---|---|---|
Suse | SUSE ratings | https://www.suse.com/support/security/rating/ | |
Suse | URL of this CSAF notice | https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2020_1392-1.json | |
Suse | URL for openSUSE-SU-2020:1392-1 | https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JNYOBI47YQLW5EKAMJETBNNXHGSR2TYF/ | |
Suse | E-Mail link for openSUSE-SU-2020:1392-1 | https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JNYOBI47YQLW5EKAMJETBNNXHGSR2TYF/ | |
Bugzilla | SUSE Bug 1175686 | https://bugzilla.suse.com/1175686 | |
CVE | SUSE CVE CVE-2020-15663 page | https://www.suse.com/security/cve/CVE-2020-15663/ | |
CVE | SUSE CVE CVE-2020-15664 page | https://www.suse.com/security/cve/CVE-2020-15664/ | |
CVE | SUSE CVE CVE-2020-15669 page | https://www.suse.com/security/cve/CVE-2020-15669/ |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/opensuse/MozillaThunderbird?arch=x86_64&distro=opensuse-leap-15.2 | opensuse | MozillaThunderbird | < 68.12.0-lp152.2.10.1 | opensuse-leap-15.2 | x86_64 | |
Affected | pkg:rpm/opensuse/MozillaThunderbird-translations-other?arch=x86_64&distro=opensuse-leap-15.2 | opensuse | MozillaThunderbird-translations-other | < 68.12.0-lp152.2.10.1 | opensuse-leap-15.2 | x86_64 | |
Affected | pkg:rpm/opensuse/MozillaThunderbird-translations-common?arch=x86_64&distro=opensuse-leap-15.2 | opensuse | MozillaThunderbird-translations-common | < 68.12.0-lp152.2.10.1 | opensuse-leap-15.2 | x86_64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |