{"schema_version":"1.7.3","id":"SUSE-SU-2019:3339-1","published":"2019-12-18T17:18:32Z","modified":"2026-02-04T03:13:54.813470Z","related":["CVE-2019-11745","CVE-2019-13722","CVE-2019-17005","CVE-2019-17008","CVE-2019-17009","CVE-2019-17010","CVE-2019-17011","CVE-2019-17012"],"upstream":["CVE-2019-11745","CVE-2019-13722","CVE-2019-17005","CVE-2019-17008","CVE-2019-17009","CVE-2019-17010","CVE-2019-17011","CVE-2019-17012"],"summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\nMozilla Thunderbird was updated to 68.3esr (MFSA 2019-38 bsc#1158328) \t  \n\nSecurity issues fixed: \n\n- CVE-2019-17008: Fixed a use-after-free in worker destruction (bmo#1546331)\n- CVE-2019-13722: Fixed a stack corruption due to incorrect number of arguments \n  in WebRTC code (bmo#1580156)\n- CVE-2019-11745: Fixed an out of bounds write in NSS when encrypting with a \n  block cipher (bmo#1586176)\n- CVE-2019-17009: Fixed an issue where updater temporary files accessible to \n  unprivileged processes (bmo#1510494)\n- CVE-2019-17010: Fixed a use-after-free when performing device orientation \n  checks (bmo#1581084)\n- CVE-2019-17005: Fixed a buffer overflow in plain text serializer (bmo#1584170)\n- CVE-2019-17011: Fixed a use-after-free when retrieving a document \n  in antitracking (bmo#1591334)\n- CVE-2019-17012: Fixed multiple memmory issues\n  (bmo#1449736, bmo#1533957, bmo#1560667,bmo#1567209, bmo#1580288, bmo#1585760, \n  bmo#1592502)\n\nOther issues addressed:\n\n- New: Message display toolbar action WebExtension API (bmo#1531597)\n- New: Navigation buttons are now available in content tabs (bmo#787683)\n- Fixed an issue where write window was not always correct (bmo#1593280)\n- Fixed toolbar issues (bmo#1584160)\n- Fixed issues with LDAP lookup when SSL was enabled (bmo#1576364)\n- Fixed an issue with scam link confirmation panel (bmo#1596413)\n- Fixed an issue with the write window where the Link Properties \n  dialog was not showing named anchors in context menu (bmo#1593629)\n- Fixed issues with calendar (bmo#1588516)\n- Fixed issues with chat where reordering via drag-and-drop was not working\n  on Instant messaging status dialog (bmo#1591505)\n","affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"68.3.0-3.61.2"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"68.3.0-3.61.2","MozillaThunderbird-translations-common":"68.3.0-3.61.2","MozillaThunderbird-translations-other":"68.3.0-3.61.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:3339-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP1","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"68.3.0-3.61.2"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"68.3.0-3.61.2","MozillaThunderbird-translations-common":"68.3.0-3.61.2","MozillaThunderbird-translations-other":"68.3.0-3.61.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:3339-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20193339-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1158328"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11745"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13722"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17005"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17008"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17009"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17010"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17011"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17012"}]}