openSUSE Security Update : MozillaThunderbird (openSUSE-2019-1484)

critical Nessus Plugin ID 125669

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for MozillaThunderbird fixes the following issues :

Mozilla Thunderbird was updated to 60.7.0

- Attachment pane of Write window no longer focussed when attaching files using a keyboard shortcut

Security issues fixed (MFSA 2019-15 boo#1135824) :

- CVE-2018-18511: Cross-origin theft of images with ImageBitmapRenderingContext

- CVE-2019-11691: Use-after-free in XMLHttpRequest

- CVE-2019-11692: Use-after-free removing listeners in the event listener manager

- CVE-2019-11693: Buffer overflow in WebGL bufferdata on Linux

- CVE-2019-11694: (Windows only) Uninitialized memory memory leakage in Windows sandbox

- CVE-2019-11698: Theft of user history data through drag and drop of hyperlinks to and from bookmarks

- CVE-2019-5798: Out-of-bounds read in Skia

- CVE-2019-7317: Use-after-free in png_image_free of libpng library

- CVE-2019-9797: Cross-origin theft of images with createImageBitmap

- CVE-2019-9800: Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7

- CVE-2019-9815: Disable hyperthreading on content JavaScript threads on macOS

- CVE-2019-9816: Type confusion with object groups and UnboxedObjects

- CVE-2019-9817: Stealing of cross-domain images using canvas

- CVE-2019-9818: Use-after-free in crash generation server

- CVE-2019-9819: Compartment mismatch with fetch API

- CVE-2019-9820: Use-after-free of ChromeEventHandler by DocShell

- Disable LTO (boo#1133267).

- Add patch to fix build using rust-1.33: (boo#1130694)

Solution

Update the affected MozillaThunderbird packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1130694

https://bugzilla.opensuse.org/show_bug.cgi?id=1133267

https://bugzilla.opensuse.org/show_bug.cgi?id=1135824

Plugin Details

Severity: Critical

ID: 125669

File Name: openSUSE-2019-1484.nasl

Version: 1.6

Type: local

Agent: unix

Published: 6/3/2019

Updated: 12/5/2022

Supported Sensors: Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.5

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:mozillathunderbird, p-cpe:/a:novell:opensuse:mozillathunderbird-buildsymbols, p-cpe:/a:novell:opensuse:mozillathunderbird-debuginfo, p-cpe:/a:novell:opensuse:mozillathunderbird-debugsource, p-cpe:/a:novell:opensuse:mozillathunderbird-translations-common, p-cpe:/a:novell:opensuse:mozillathunderbird-translations-other, cpe:/o:novell:opensuse:42.3

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/2/2019

Vulnerability Publication Date: 2/4/2019

Reference Information

CVE: CVE-2018-18511, CVE-2019-11691, CVE-2019-11692, CVE-2019-11693, CVE-2019-11694, CVE-2019-11698, CVE-2019-5798, CVE-2019-7317, CVE-2019-9797, CVE-2019-9800, CVE-2019-9815, CVE-2019-9816, CVE-2019-9817, CVE-2019-9818, CVE-2019-9819, CVE-2019-9820