Oval Definition:oval:org.opensuse.security:def:95368
Revision Date:2022-06-13Version:1
Title:Security update for MozillaThunderbird (Important)
Description:

This update for MozillaThunderbird fixes the following issues:

Update to Mozilla Thunderbird 91.9.1

MFSA 2022-19 (bsc#1199768):

- CVE-2022-1802: Prototype pollution in Top-Level Await implementation (bmo#1770137). - CVE-2022-1529: Untrusted input used in JavaScript object indexing, leading to prototype pollution (bmo#1770048). Update to Mozilla Thunderbird 91.10

MFSA 2022-22 (bsc#1200027):

- CVE-2022-31736: Cross-Origin resource's length leaked (bmo#1735923) - CVE-2022-31737: Heap buffer overflow in WebGL (bmo#1743767) - CVE-2022-31738: Browser window spoof using fullscreen mode (bmo#1756388) - CVE-2022-31739: Attacker-influenced path traversal when saving downloaded files (bmo#1765049) - CVE-2022-31740: Register allocation problem in WASM on arm64 (bmo#1766806) - CVE-2022-31741: Uninitialized variable leads to invalid memory read (bmo#1767590) - CVE-2022-1834: Braille space character caused incorrect sender email to be shown for a digitally signed email (bmo#1767816) - CVE-2022-31742: Querying a WebAuthn token with a large number of allowCredential entries may have leaked cross-origin information (bmo#1730434) - CVE-2022-31747: Memory safety bugs fixed in Thunderbird 91.10 (bmo#1760765, bmo#1765610, bmo#1766283, bmo#1767365, bmo#1768559, bmo#1768734)
Family:unixClass:patch
Status:Reference(s):1180014
1189320
1199768
1200027
CVE-2021-2372
CVE-2021-2389
CVE-2022-1529
CVE-2022-1802
CVE-2022-1834
CVE-2022-31736
CVE-2022-31737
CVE-2022-31738
CVE-2022-31739
CVE-2022-31740
CVE-2022-31741
CVE-2022-31742
CVE-2022-31747
SUSE-SU-2022:2062-1
Platform(s):SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2
SUSE Linux Enterprise Module for Package Hub 15 SP4
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Package Hub 15 SP4 is installed
  • AND Package Information
  • MozillaThunderbird-91.10.0-150200.8.73.1 is installed
  • OR MozillaThunderbird-translations-common-91.10.0-150200.8.73.1 is installed
  • OR MozillaThunderbird-translations-other-91.10.0-150200.8.73.1 is installed
  • BACK