Oval Definition:oval:org.opensuse.security:def:66329
Revision Date:2020-12-01Version:1
Title:Security update for MozillaThunderbird (Important)
Description:

This update for MozillaThunderbird fixes the following issues:

TODO - Mozilla Thunderbird 78.5.0 * new: OpenPGP: Added option to disable attaching the public key to a signed message (bmo#1654950) * new: MailExtensions: 'compose_attachments' context added to Menus API (bmo#1670822) * new: MailExtensions: Menus API now available on displayed messages (bmo#1670825) * changed: MailExtensions: browser.tabs.create will now wait for 'mail-delayed-startup-finished' event (bmo#1674407) * fixed: OpenPGP: Support for inline PGP messages improved (bmo#1672851) * fixed: OpenPGP: Message security dialog showed unverified keys as unavailable (bmo#1675285) * fixed: Chat: New chat contact menu item did not function (bmo#1663321) * fixed: Various theme and usability improvements (bmo#1673861) * fixed: Various security fixes MFSA 2020-52 (bsc#1178894) * CVE-2020-26951 (bmo#1667113) Parsing mismatches could confuse and bypass security sanitizer for chrome privileged code * CVE-2020-16012 (bmo#1642028) Variable time processing of cross-origin images during drawImage calls * CVE-2020-26953 (bmo#1656741) Fullscreen could be enabled without displaying the security UI * CVE-2020-26956 (bmo#1666300) XSS through paste (manual and clipboard API) * CVE-2020-26958 (bmo#1669355) Requests intercepted through ServiceWorkers lacked MIME type restrictions * CVE-2020-26959 (bmo#1669466) Use-after-free in WebRequestService * CVE-2020-26960 (bmo#1670358) Potential use-after-free in uses of nsTArray * CVE-2020-15999 (bmo#1672223) Heap buffer overflow in freetype * CVE-2020-26961 (bmo#1672528) DoH did not filter IPv4 mapped IP Addresses * CVE-2020-26965 (bmo#1661617) Software keyboards may have remembered typed passwords * CVE-2020-26966 (bmo#1663571) Single-word search queries were also broadcast to local network * CVE-2020-26968 (bmo#1551615, bmo#1607762, bmo#1656697, bmo#1657739, bmo#1660236, bmo#1667912, bmo#1671479, bmo#1671923) Memory safety bugs fixed in Thunderbird 78.5

- Mozilla Thunderbird 78.4.3 * fixed: User interface was inconsistent when switching from the default theme to the dark theme and back to the default theme (bmo#1659282) * fixed: Email subject would disappear when hovering over it with the mouse when using Windows 7 Classic theme (bmo#1675970)
Family:unixClass:patch
Status:Reference(s):1178894
CVE-2017-1000251
CVE-2017-12153
CVE-2017-13080
CVE-2017-14051
CVE-2017-16536
CVE-2017-16537
CVE-2017-16646
CVE-2017-16648
CVE-2017-5715
CVE-2017-5753
CVE-2017-5754
CVE-2018-10323
CVE-2018-12232
CVE-2018-13053
CVE-2018-20669
CVE-2019-0154
CVE-2019-0155
CVE-2019-10220
CVE-2019-11477
CVE-2019-11478
CVE-2019-11479
CVE-2019-14615
CVE-2019-14814
CVE-2019-14815
CVE-2019-14816
CVE-2019-14895
CVE-2019-14896
CVE-2019-14897
CVE-2019-14901
CVE-2019-15030
CVE-2019-15031
CVE-2019-15098
CVE-2019-15099
CVE-2019-15290
CVE-2019-15291
CVE-2019-15504
CVE-2019-16231
CVE-2019-16232
CVE-2019-16233
CVE-2019-16234
CVE-2019-17133
CVE-2019-17666
CVE-2019-18198
CVE-2019-18660
CVE-2019-18683
CVE-2019-18786
CVE-2019-18808
CVE-2019-18809
CVE-2019-18811
CVE-2019-18812
CVE-2019-18813
CVE-2019-19037
CVE-2019-19043
CVE-2019-19044
CVE-2019-19045
CVE-2019-19046
CVE-2019-19047
CVE-2019-19048
CVE-2019-19049
CVE-2019-19050
CVE-2019-19051
CVE-2019-19052
CVE-2019-19053
CVE-2019-19054
CVE-2019-19055
CVE-2019-19056
CVE-2019-19057
CVE-2019-19058
CVE-2019-19060
CVE-2019-19061
CVE-2019-19062
CVE-2019-19063
CVE-2019-19064
CVE-2019-19065
CVE-2019-19066
CVE-2019-19067
CVE-2019-19068
CVE-2019-19069
CVE-2019-19070
CVE-2019-19071
CVE-2019-19072
CVE-2019-19073
CVE-2019-19074
CVE-2019-19075
CVE-2019-19077
CVE-2019-19078
CVE-2019-19080
CVE-2019-19081
CVE-2019-19082
CVE-2019-19083
CVE-2019-19241
CVE-2019-19252
CVE-2019-19332
CVE-2019-19338
CVE-2019-19447
CVE-2019-19523
CVE-2019-19524
CVE-2019-19525
CVE-2019-19526
CVE-2019-19528
CVE-2019-19529
CVE-2019-19532
CVE-2019-19533
CVE-2019-19534
CVE-2019-19602
CVE-2019-19767
CVE-2019-19768
CVE-2019-19770
CVE-2019-19807
CVE-2019-19922
CVE-2019-19947
CVE-2019-19965
CVE-2019-20422
CVE-2019-3016
CVE-2019-8912
CVE-2020-0110
CVE-2020-0543
CVE-2020-10690
CVE-2020-10757
CVE-2020-10942
CVE-2020-11494
CVE-2020-11608
CVE-2020-11884
CVE-2020-12464
CVE-2020-12465
CVE-2020-12652
CVE-2020-12653
CVE-2020-12654
CVE-2020-12655
CVE-2020-12657
CVE-2020-12659
CVE-2020-15999
CVE-2020-16012
CVE-2020-1749
CVE-2020-26951
CVE-2020-26953
CVE-2020-26956
CVE-2020-26958
CVE-2020-26959
CVE-2020-26960
CVE-2020-26961
CVE-2020-26965
CVE-2020-26966
CVE-2020-26968
CVE-2020-2732
CVE-2020-8428
CVE-2020-8647
CVE-2020-8648
CVE-2020-8649
CVE-2020-8835
CVE-2020-8992
CVE-2020-9383
SUSE-SU-2020:3528-1
Platform(s):SUSE Linux Enterprise Module for Basesystem 15 SP2
SUSE Linux Enterprise Workstation Extension 15 SP1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • AND Package Information
  • kernel-default-5.3.18-22 is installed
  • OR kernel-default-devel-5.3.18-22 is installed
  • OR kernel-devel-5.3.18-22 is installed
  • OR kernel-macros-5.3.18-22 is installed
  • OR kernel-preempt-5.3.18-22 is installed
  • OR kernel-zfcpdump-5.3.18-22 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 15 SP1 is installed
  • AND Package Information
  • MozillaThunderbird-78.5.0-3.107 is installed
  • OR MozillaThunderbird-translations-common-78.5.0-3.107 is installed
  • OR MozillaThunderbird-translations-other-78.5.0-3.107 is installed
  • BACK