Oval Definition:oval:org.opensuse.security:def:50844
Revision Date:2020-12-01Version:1
Title:Security update for MozillaThunderbird and mozilla-nspr (Important)
Description:

This update for MozillaThunderbird and mozilla-nspr fixes the following issues:

- Mozilla Thunderbird 78.4 * new: MailExtensions: browser.tabs.sendMessage API added * new: MailExtensions: messageDisplayScripts API added * changed: Yahoo and AOL mail users using password authentication will be migrated to OAuth2 * changed: MailExtensions: messageDisplay APIs extended to support multiple selected messages * changed: MailExtensions: compose.begin functions now support creating a message with attachments * fixed: Thunderbird could freeze when updating global search index * fixed: Multiple issues with handling of self-signed SSL certificates addressed * fixed: Recipient address fields in compose window could expand to fill all available space * fixed: Inserting emoji characters in message compose window caused unexpected behavior * fixed: Button to restore default folder icon color was not keyboard accessible * fixed: Various keyboard navigation fixes * fixed: Various color-related theme fixes * fixed: MailExtensions: Updating attachments with onBeforeSend.addListener() did not work MFSA 2020-47 (bsc#1177977) * CVE-2020-15969 Use-after-free in usersctp * CVE-2020-15683 Memory safety bugs fixed in Thunderbird 78.4 - Mozilla Thunderbird 78.3.3 * OpenPGP: Improved support for encrypting with subkeys * OpenPGP message status icons were not visible in message header pane * Creating a new calendar event did not require an event title - Mozilla Thunderbird 78.3.2 (bsc#1176899) * OpenPGP: Improved support for encrypting with subkeys * OpenPGP: Encrypted messages with international characters were sometimes displayed incorrectly * Single-click deletion of recipient pills with middle mouse button restored * Searching an address book list did not display results * Dark mode, high contrast, and Windows theming fixes - Mozilla Thunderbird 78.3.1 * fix crash in nsImapProtocol::CreateNewLineFromSocket - Mozilla Thunderbird 78.3.0 MFSA 2020-44 (bsc#1176756) * CVE-2020-15677 Download origin spoofing via redirect * CVE-2020-15676 XSS when pasting attacker-controlled data into a contenteditable element * CVE-2020-15678 When recursing through layers while scrolling, an iterator may have become invalid, resulting in a potential use-after- free scenario * CVE-2020-15673 Memory safety bugs fixed in Thunderbird 78.3

- update mozilla-nspr to version 4.25.1 * The macOS platform code for shared library loading was changed to support macOS 11. * Dependency needed for the MozillaThunderbird udpate
Family:unixClass:patch
Status:Reference(s):1051510
1065729
1071995
1104967
1106843
1113719
1118987
1132501
1134157
1134853
1140709
1143463
1143777
1143817
1143818
1143819
1143820
1143821
1143823
1143824
1143825
1143827
1143828
1143830
1143831
1151455
1152107
1153095
1153245
1154401
1156146
1156188
1157179
1158755
1159913
1160903
1160905
1162002
1162197
1162198
1162200
1165548
1165631
1167209
1168669
1169511
1170011
1171078
1171352
1171673
1171732
1171868
1172257
1172775
1172781
1172782
1172783
1172999
1173032
1173265
1173280
1173514
1173567
1173573
1173659
1173999
1174000
1174115
1174230
1174462
1174543
1175686
1176384
1176409
1176412
1176756
1176899
1177977
862963
941629
CVE-2018-11805
CVE-2018-18751
CVE-2019-10691
CVE-2019-11059
CVE-2019-11690
CVE-2019-12838
CVE-2019-13103
CVE-2019-14192
CVE-2019-14193
CVE-2019-14194
CVE-2019-14195
CVE-2019-14196
CVE-2019-14197
CVE-2019-14198
CVE-2019-14199
CVE-2019-14200
CVE-2019-14201
CVE-2019-14202
CVE-2019-14203
CVE-2019-14204
CVE-2019-14818
CVE-2019-16746
CVE-2019-18804
CVE-2019-18902
CVE-2019-20908
CVE-2019-5108
CVE-2020-0305
CVE-2020-10648
CVE-2020-10766
CVE-2020-10767
CVE-2020-10768
CVE-2020-10769
CVE-2020-10773
CVE-2020-12402
CVE-2020-12771
CVE-2020-12888
CVE-2020-13974
CVE-2020-14392
CVE-2020-14393
CVE-2020-14416
CVE-2020-15393
CVE-2020-15663
CVE-2020-15664
CVE-2020-15669
CVE-2020-15673
CVE-2020-15676
CVE-2020-15677
CVE-2020-15678
CVE-2020-15683
CVE-2020-15780
CVE-2020-15969
CVE-2020-1749
CVE-2020-1930
CVE-2020-1931
CVE-2020-2754
CVE-2020-2755
CVE-2020-2756
CVE-2020-2757
CVE-2020-2773
CVE-2020-2781
CVE-2020-2800
CVE-2020-2803
CVE-2020-2805
CVE-2020-2830
CVE-2020-7216
CVE-2020-8432
SUSE-SU-2019:0997-1
SUSE-SU-2019:2989-1
SUSE-SU-2019:3033-1
SUSE-SU-2020:0263-1
SUSE-SU-2020:0439-1
SUSE-SU-2020:0811-1
SUSE-SU-2020:0868-1
SUSE-SU-2020:1213-1
SUSE-SU-2020:1850-1
SUSE-SU-2020:2645-1
SUSE-SU-2020:3091-1
Platform(s):SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Module for additional PackageHub packages 15
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Module for High Performance Computing 15 SP1
SUSE Linux Enterprise Module for Live Patching 15
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2
SUSE Linux Enterprise Module for Public Cloud 15 SP1
SUSE Linux Enterprise Module for Server Applications 15
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 15-LTSS
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15 SP1
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP3 is installed
  • AND Package Information
  • dhcp-4.2.4.P2-0.24 is installed
  • OR dhcp-client-4.2.4.P2-0.24 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 is installed
  • AND Package Information
  • bind-libs-9.9.5P1-1 is installed
  • OR bind-libs-32bit-9.9.5P1-1 is installed
  • OR bind-utils-9.9.5P1-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP1 is installed
  • AND busybox-1.21.1-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP2 is installed
  • AND Package Information
  • cyrus-sasl-2.1.26-7 is installed
  • OR cyrus-sasl-32bit-2.1.26-7 is installed
  • OR cyrus-sasl-crammd5-2.1.26-7 is installed
  • OR cyrus-sasl-crammd5-32bit-2.1.26-7 is installed
  • OR cyrus-sasl-digestmd5-2.1.26-7 is installed
  • OR cyrus-sasl-digestmd5-32bit-2.1.26-7 is installed
  • OR cyrus-sasl-gssapi-2.1.26-7 is installed
  • OR cyrus-sasl-gssapi-32bit-2.1.26-7 is installed
  • OR cyrus-sasl-plain-2.1.26-7 is installed
  • OR cyrus-sasl-plain-32bit-2.1.26-7 is installed
  • OR cyrus-sasl-saslauthd-2.1.26-7 is installed
  • OR libsasl2-3-2.1.26-7 is installed
  • OR libsasl2-3-32bit-2.1.26-7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • NetworkManager-1.0.12-12 is installed
  • OR NetworkManager-lang-1.0.12-12 is installed
  • OR libnm-glib-vpn1-1.0.12-12 is installed
  • OR libnm-glib4-1.0.12-12 is installed
  • OR libnm-util2-1.0.12-12 is installed
  • OR libnm0-1.0.12-12 is installed
  • OR typelib-1_0-NM-1_0-1.0.12-12 is installed
  • OR typelib-1_0-NMClient-1_0-1.0.12-12 is installed
  • OR typelib-1_0-NetworkManager-1_0-1.0.12-12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • AND Package Information
  • elfutils-0.158-6 is installed
  • OR libasm1-0.158-6 is installed
  • OR libdw1-0.158-6 is installed
  • OR libdw1-32bit-0.158-6 is installed
  • OR libebl1-0.158-6 is installed
  • OR libebl1-32bit-0.158-6 is installed
  • OR libelf-devel-0.158-6 is installed
  • OR libelf1-0.158-6 is installed
  • OR libelf1-32bit-0.158-6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for additional PackageHub packages 15 is installed
  • AND djvulibre-3.5.27-3.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • mozilla-nspr-4.25.1-3.15 is installed
  • OR mozilla-nspr-32bit-4.25.1-3.15 is installed
  • OR mozilla-nspr-devel-4.25.1-3.15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for High Performance Computing 15 SP1 is installed
  • AND Package Information
  • libslurm32-17.11.13-6.18 is installed
  • OR slurm-17.11.13-6.18 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Live Patching 15 is installed
  • AND Package Information
  • kernel-livepatch-4_12_14-150_47-default-3-2 is installed
  • OR kernel-livepatch-SLE15_Update_17-3-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 is installed
  • AND Package Information
  • gettext-java-0.19.8.1-4.8 is installed
  • OR gettext-runtime-0.19.8.1-4.8 is installed
  • OR gettext-runtime-mini-0.19.8.1-4.8 is installed
  • OR gettext-runtime-mini-tools-doc-0.19.8.1-4.8 is installed
  • OR gettext-runtime-tools-doc-0.19.8.1-4.8 is installed
  • OR gettext-tools-mini-0.19.8.1-4.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2 is installed
  • AND Package Information
  • java-1_8_0-openj9-1.8.0.252-3.4 is installed
  • OR java-1_8_0-openj9-accessibility-1.8.0.252-3.4 is installed
  • OR java-1_8_0-openj9-demo-1.8.0.252-3.4 is installed
  • OR java-1_8_0-openj9-devel-1.8.0.252-3.4 is installed
  • OR java-1_8_0-openj9-headless-1.8.0.252-3.4 is installed
  • OR java-1_8_0-openj9-javadoc-1.8.0.252-3.4 is installed
  • OR java-1_8_0-openj9-src-1.8.0.252-3.4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Public Cloud 15 SP1 is installed
  • AND Package Information
  • rmt-server-2.5.7-3.15 is installed
  • OR rmt-server-pubcloud-2.5.7-3.15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 is installed
  • AND Package Information
  • dovecot23-2.3.3-4.13 is installed
  • OR dovecot23-backend-mysql-2.3.3-4.13 is installed
  • OR dovecot23-backend-pgsql-2.3.3-4.13 is installed
  • OR dovecot23-backend-sqlite-2.3.3-4.13 is installed
  • OR dovecot23-devel-2.3.3-4.13 is installed
  • OR dovecot23-fts-2.3.3-4.13 is installed
  • OR dovecot23-fts-lucene-2.3.3-4.13 is installed
  • OR dovecot23-fts-solr-2.3.3-4.13 is installed
  • OR dovecot23-fts-squat-2.3.3-4.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • gnome-keyring-3.10.1-11 is installed
  • OR gnome-keyring-32bit-3.10.1-11 is installed
  • OR gnome-keyring-lang-3.10.1-11 is installed
  • OR gnome-keyring-pam-3.10.1-11 is installed
  • OR gnome-keyring-pam-32bit-3.10.1-11 is installed
  • OR libgck-modules-gnome-keyring-3.10.1-11 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • kgraft-patch-3_12_74-60_64_57-default-4-2 is installed
  • OR kgraft-patch-3_12_74-60_64_57-xen-4-2 is installed
  • OR kgraft-patch-SLE12-SP1_Update_20-4-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • glibc-2.22-49 is installed
  • OR glibc-32bit-2.22-49 is installed
  • OR glibc-devel-2.22-49 is installed
  • OR glibc-devel-32bit-2.22-49 is installed
  • OR glibc-html-2.22-49 is installed
  • OR glibc-i18ndata-2.22-49 is installed
  • OR glibc-info-2.22-49 is installed
  • OR glibc-locale-2.22-49 is installed
  • OR glibc-locale-32bit-2.22-49 is installed
  • OR glibc-profile-2.22-49 is installed
  • OR glibc-profile-32bit-2.22-49 is installed
  • OR nscd-2.22-49 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • kernel-default-4.4.121-92.85 is installed
  • OR kernel-default-base-4.4.121-92.85 is installed
  • OR kernel-default-devel-4.4.121-92.85 is installed
  • OR kernel-devel-4.4.121-92.85 is installed
  • OR kernel-macros-4.4.121-92.85 is installed
  • OR kernel-source-4.4.121-92.85 is installed
  • OR kernel-syms-4.4.121-92.85 is installed
  • OR kgraft-patch-4_4_121-92_85-default-1-3.5 is installed
  • OR kgraft-patch-SLE12-SP2_Update_23-1-3.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • libmysqlclient18-10.0.35-29.20 is installed
  • OR libmysqlclient18-32bit-10.0.35-29.20 is installed
  • OR mariadb-10.0.35-29.20 is installed
  • OR mariadb-client-10.0.35-29.20 is installed
  • OR mariadb-errormessages-10.0.35-29.20 is installed
  • OR mariadb-tools-10.0.35-29.20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_90-92_45-default-8-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_14-8-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • dbus-1-1.8.22-28 is installed
  • OR dbus-1-x11-1.8.22-28 is installed
  • OR libdbus-1-3-1.8.22-28 is installed
  • OR libdbus-1-3-32bit-1.8.22-28 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_180-94_97-default-3-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_26-3-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • libcgroup-0.41.rc1-10.9 is installed
  • OR libcgroup-tools-0.41.rc1-10.9 is installed
  • OR libcgroup1-0.41.rc1-10.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • libykcs11-1-1.5.0-3 is installed
  • OR libykpiv1-1.5.0-3 is installed
  • OR yubico-piv-tool-1.5.0-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 15-LTSS is installed
  • AND Package Information
  • libfreebl3-3.53.1-3.45 is installed
  • OR libfreebl3-32bit-3.53.1-3.45 is installed
  • OR libfreebl3-hmac-3.53.1-3.45 is installed
  • OR libfreebl3-hmac-32bit-3.53.1-3.45 is installed
  • OR libsoftokn3-3.53.1-3.45 is installed
  • OR libsoftokn3-32bit-3.53.1-3.45 is installed
  • OR libsoftokn3-hmac-3.53.1-3.45 is installed
  • OR libsoftokn3-hmac-32bit-3.53.1-3.45 is installed
  • OR mozilla-nss-3.53.1-3.45 is installed
  • OR mozilla-nss-32bit-3.53.1-3.45 is installed
  • OR mozilla-nss-certs-3.53.1-3.45 is installed
  • OR mozilla-nss-certs-32bit-3.53.1-3.45 is installed
  • OR mozilla-nss-devel-3.53.1-3.45 is installed
  • OR mozilla-nss-sysinit-3.53.1-3.45 is installed
  • OR mozilla-nss-tools-3.53.1-3.45 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 15 is installed
  • AND Package Information
  • kernel-default-4.12.14-150.55 is installed
  • OR kernel-default-base-4.12.14-150.55 is installed
  • OR kernel-default-devel-4.12.14-150.55 is installed
  • OR kernel-devel-4.12.14-150.55 is installed
  • OR kernel-docs-4.12.14-150.55 is installed
  • OR kernel-macros-4.12.14-150.55 is installed
  • OR kernel-obs-build-4.12.14-150.55 is installed
  • OR kernel-source-4.12.14-150.55 is installed
  • OR kernel-syms-4.12.14-150.55 is installed
  • OR kernel-vanilla-4.12.14-150.55 is installed
  • OR kernel-vanilla-base-4.12.14-150.55 is installed
  • OR reiserfs-kmp-default-4.12.14-150.55 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 15 SP1 is installed
  • AND Package Information
  • MozillaThunderbird-68.9.0-3.85 is installed
  • OR MozillaThunderbird-translations-common-68.9.0-3.85 is installed
  • OR MozillaThunderbird-translations-other-68.9.0-3.85 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND Package Information
  • openstack-trove-4.0.1~a0~dev2-2 is installed
  • OR openstack-trove-api-4.0.1~a0~dev2-2 is installed
  • OR openstack-trove-conductor-4.0.1~a0~dev2-2 is installed
  • OR openstack-trove-guestagent-4.0.1~a0~dev2-2 is installed
  • OR openstack-trove-taskmanager-4.0.1~a0~dev2-2 is installed
  • OR python-trove-4.0.1~a0~dev2-2 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • openstack-glance-13.0.1~a0~dev6-4.3 is installed
  • OR openstack-glance-api-13.0.1~a0~dev6-4.3 is installed
  • OR openstack-glance-doc-13.0.1~a0~dev6-4.3 is installed
  • OR openstack-glance-glare-13.0.1~a0~dev6-4.3 is installed
  • OR openstack-glance-registry-13.0.1~a0~dev6-4.3 is installed
  • OR python-glance-13.0.1~a0~dev6-4.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • ruby2.1-rubygem-loofah-2.0.2-3.8 is installed
  • OR rubygem-loofah-2.0.2-3.8 is installed
  • BACK