[openSUSE-SU-2020:1392-1] Security update for MozillaThunderbird

Severity Important
Affected Packages 3
CVEs 3

Security update for MozillaThunderbird

This update for MozillaThunderbird fixes the following issues:

  • Mozilla Thunderbird was updated to 68.12 (bsc#1175686)

  • CVE-2020-15663: Downgrade attack on the Mozilla Maintenance Service could
    have resulted in escalation of privilege

  • CVE-2020-15664: Attacker-induced prompt for extension installation

  • CVE-2020-15669: Use-After-Free when aborting an operation

This update was imported from the SUSE:SLE-15:Update update project.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/MozillaThunderbird?arch=x86_64&distro=opensuse-leap-15.2 opensuse MozillaThunderbird < 68.12.0-lp152.2.10.1 opensuse-leap-15.2 x86_64
Affected pkg:rpm/opensuse/MozillaThunderbird-translations-other?arch=x86_64&distro=opensuse-leap-15.2 opensuse MozillaThunderbird-translations-other < 68.12.0-lp152.2.10.1 opensuse-leap-15.2 x86_64
Affected pkg:rpm/opensuse/MozillaThunderbird-translations-common?arch=x86_64&distro=opensuse-leap-15.2 opensuse MozillaThunderbird-translations-common < 68.12.0-lp152.2.10.1 opensuse-leap-15.2 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...