OPENSUSE-SU-2016:1769-1
Vulnerability Summary
Timeline
Description
Security update for Mozilla Thunderbird This update contains Mozilla Thunderbird 45.2. (boo#983549) It fixes security issues mostly affecting the e-mail program when used in a browser context, such as viewing a web page or HTMl formatted e-mail. The following vulnerabilities were fixed: - CVE-2016-2818, CVE-2016-2815: Memory safety bugs (boo#983549, MFSA2016-49) Contains the following security fixes from the 45.1 release: (boo#977333) - CVE-2016-2806, CVE-2016-2807: Miscellaneous memory safety hazards (boo#977375, boo#977376, MFSA 2016-39) Contains the following security fixes from the 45.0 release: (boo#969894) - CVE-2016-1952, CVE-2016-1953: Miscellaneous memory safety hazards (MFSA 2016-16) - CVE-2016-1954: Local file overwriting and potential privilege escalation through CSP reports (MFSA 2016-17) - CVE-2016-1955: CSP reports fail to strip location information for embedded iframe pages (MFSA 2016-18) - CVE-2016-1956: Linux video memory DOS with Intel drivers (MFSA 2016-19) - CVE-2016-1957: Memory leak in libstagefright when deleting an array during MP4 processing (MFSA 2016-20) - CVE-2016-1960: Use-after-free in HTML5 string parser (MFSA 2016-23) - CVE-2016-1961: Use-after-free in SetBody (MFSA 2016-24) - CVE-2016-1964: Use-after-free during XML transformations (MFSA 2016-27) - CVE-2016-1974: Out-of-bounds read in HTML parser following a failed allocation (MFSA 2016-34) The graphite font shaping library was disabled, addressing the following font vulnerabilities: - MFSA 2016-37/CVE-2016-1977/CVE-2016-2790/CVE-2016-2791/ CVE-2016-2792/CVE-2016-2793/CVE-2016-2794/CVE-2016-2795/ CVE-2016-2796/CVE-2016-2797/CVE-2016-2798/CVE-2016-2799/ CVE-2016-2800/CVE-2016-2801/CVE-2016-2802 The following tracked packaging changes are included: - fix build issues with gcc/binutils combination used in Leap 42.2 (boo#984637) - gcc6 fixes (boo#986162) - running on 48bit va aarch64 (boo#984126)
Affected Systems
- suse•MozillaThunderbird&distro=SUSE Package Hub 12
< 45.2-6.1
References (37)
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5
- https://bugzilla.suse.com/969894
- https://bugzilla.suse.com/977333
- https://bugzilla.suse.com/977375
- https://bugzilla.suse.com/977376
- https://bugzilla.suse.com/983549
- https://bugzilla.suse.com/984126
- https://bugzilla.suse.com/984637
- https://bugzilla.suse.com/986162
- https://www.suse.com/security/cve/CVE-2016-1952
- https://www.suse.com/security/cve/CVE-2016-1953
- https://www.suse.com/security/cve/CVE-2016-1954
- https://www.suse.com/security/cve/CVE-2016-1955
- https://www.suse.com/security/cve/CVE-2016-1956
- https://www.suse.com/security/cve/CVE-2016-1957
- https://www.suse.com/security/cve/CVE-2016-1960
- https://www.suse.com/security/cve/CVE-2016-1961
- https://www.suse.com/security/cve/CVE-2016-1964
- https://www.suse.com/security/cve/CVE-2016-1974
- https://www.suse.com/security/cve/CVE-2016-1977
- https://www.suse.com/security/cve/CVE-2016-2790
- https://www.suse.com/security/cve/CVE-2016-2791
- https://www.suse.com/security/cve/CVE-2016-2792
- https://www.suse.com/security/cve/CVE-2016-2793
- https://www.suse.com/security/cve/CVE-2016-2794
- https://www.suse.com/security/cve/CVE-2016-2795
- https://www.suse.com/security/cve/CVE-2016-2796
- https://www.suse.com/security/cve/CVE-2016-2797
- https://www.suse.com/security/cve/CVE-2016-2798
- https://www.suse.com/security/cve/CVE-2016-2799
- https://www.suse.com/security/cve/CVE-2016-2800
- https://www.suse.com/security/cve/CVE-2016-2801
- https://www.suse.com/security/cve/CVE-2016-2802
- https://www.suse.com/security/cve/CVE-2016-2806
- https://www.suse.com/security/cve/CVE-2016-2807
- https://www.suse.com/security/cve/CVE-2016-2815
- https://www.suse.com/security/cve/CVE-2016-2818