You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa MozillaThunderbird

Sigurnosni nedostaci programskog paketa MozillaThunderbird

  • Detalji os-a: WN7
  • Važnost: URG
  • Operativni sustavi: L
  • Kategorije: LSU

openSUSE Security Update: Security update for MozillaThunderbird
______________________________________________________________________________

Announcement ID: openSUSE-SU-2019:1594-1
Rating: critical
References: #1138614 #1138872
Cross-References: CVE-2019-11707 CVE-2019-11708
Affected Products:
openSUSE Leap 42.3
______________________________________________________________________________

An update that fixes two vulnerabilities is now available.

Description:

This update for MozillaThunderbird to version 60.7.2 fixes the following
issues:

Security issues fixed:

– CVE-2019-11707: Fixed a type confusion vulnerability in Arrary.pop
(bsc#1138614)
– CVE-2019-11708: Fixed an issue which could have allowed sandbox escape
using Prompt:Open (bsc#1138872).

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

– openSUSE Leap 42.3:

zypper in -t patch openSUSE-2019-1594=1

Package List:

– openSUSE Leap 42.3 (x86_64):

MozillaThunderbird-60.7.2-98.1
MozillaThunderbird-buildsymbols-60.7.2-98.1
MozillaThunderbird-debuginfo-60.7.2-98.1
MozillaThunderbird-debugsource-60.7.2-98.1
MozillaThunderbird-translations-common-60.7.2-98.1
MozillaThunderbird-translations-other-60.7.2-98.1

References:

https://www.suse.com/security/cve/CVE-2019-11707.html
https://www.suse.com/security/cve/CVE-2019-11708.html
https://bugzilla.suse.com/1138614
https://bugzilla.suse.com/1138872


To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org

AutorJosip Papratovic
Cert idNCERT-REF-2019-06-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programske biblioteke Libvirt

Otkriveni su sigurnosni nedostaci programske biblioteke Libvirt za operacijski sustav Debian. Otkriveni nedostaci potencijalnim napadačima omogućuju stjecanje uvećanih ovlasti. Savjetuje...

Close