Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:2179-1

Опубликовано: 10 авг. 2020
Источник: suse-cvrf

Описание

Security update for MozillaThunderbird

This update for MozillaThunderbird fixes the following issues:

  • Updated to Mozilla Thunderbird 68.11:
    • Fixed various security issues (MFSA-2020-35, bsc#1174538).
    • Fixed CVE-2020-15652: Potential leak of redirect targets when loading scripts in a worker (bsc#1174538).
    • Fixed CVE-2020-6514: WebRTC data channel leaks internal address to peer (bsc#1174538).
    • Fixed CVE-2020-6463: Use-after-free in ANGLE gl::Texture::onUnbindAsSamplerTexture (bsc#1174538).
    • Fixed CVE-2020-15659: Memory safety bugs fixed in Thunderbird 68.11 (bsc#1174538).
    • Fixed a bug with FileLink attachments included as a link and file when added from a network drive via drag & drop (bmo#793118).

Список пакетов

SUSE Linux Enterprise Workstation Extension 15 SP1
MozillaThunderbird-68.11.0-3.91.1
MozillaThunderbird-translations-common-68.11.0-3.91.1
MozillaThunderbird-translations-other-68.11.0-3.91.1
SUSE Linux Enterprise Workstation Extension 15 SP2
MozillaThunderbird-68.11.0-3.91.1
MozillaThunderbird-translations-common-68.11.0-3.91.1
MozillaThunderbird-translations-other-68.11.0-3.91.1

Описание

By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.


Затронутые продукты
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-68.11.0-3.91.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-common-68.11.0-3.91.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-other-68.11.0-3.91.1
SUSE Linux Enterprise Workstation Extension 15 SP2:MozillaThunderbird-68.11.0-3.91.1

Ссылки

Описание

Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.


Затронутые продукты
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-68.11.0-3.91.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-common-68.11.0-3.91.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-other-68.11.0-3.91.1
SUSE Linux Enterprise Workstation Extension 15 SP2:MozillaThunderbird-68.11.0-3.91.1

Ссылки

Описание

Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-68.11.0-3.91.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-common-68.11.0-3.91.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-other-68.11.0-3.91.1
SUSE Linux Enterprise Workstation Extension 15 SP2:MozillaThunderbird-68.11.0-3.91.1

Ссылки

Описание

Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.


Затронутые продукты
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-68.11.0-3.91.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-common-68.11.0-3.91.1
SUSE Linux Enterprise Workstation Extension 15 SP1:MozillaThunderbird-translations-other-68.11.0-3.91.1
SUSE Linux Enterprise Workstation Extension 15 SP2:MozillaThunderbird-68.11.0-3.91.1

Ссылки
Уязвимость SUSE-SU-2020:2179-1