{"schema_version":"1.7.3","id":"openSUSE-SU-2019:1990-1","published":"2019-08-23T10:26:10Z","modified":"2026-02-04T04:39:58.745204Z","related":["CVE-2019-11709","CVE-2019-11711","CVE-2019-11712","CVE-2019-11713","CVE-2019-11715","CVE-2019-11717","CVE-2019-11719","CVE-2019-11729","CVE-2019-11730","CVE-2019-9811"],"upstream":["CVE-2019-11709","CVE-2019-11711","CVE-2019-11712","CVE-2019-11713","CVE-2019-11715","CVE-2019-11717","CVE-2019-11719","CVE-2019-11729","CVE-2019-11730","CVE-2019-9811"],"summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\n- Generate langpacks sequentially to avoid file corruption\n  from racy file writes (boo#1137970)\n\n- Mozilla Thunderbird 60.8.0\n  * Calendar: Problems when editing event times, some related to\n    AM/PM setting in non-English locales\n  MFSA 2019-23   (boo#1140868)\n  * CVE-2019-9811 (bmo#1538007, bmo#1539598, bmo#1563327)\n    Sandbox escape via installation of malicious languagepack\n  * CVE-2019-11711 (bmo#1552541)\n    Script injection within domain through inner window reuse\n  * CVE-2019-11712 (bmo#1543804)\n    Cross-origin POST requests can be made with NPAPI plugins by\n    following 308 redirects\n  * CVE-2019-11713 (bmo#1528481)\n    Use-after-free with HTTP/2 cached stream\n  * CVE-2019-11729 (bmo#1515342)\n    Empty or malformed p256-ECDH public keys may trigger a segmentation fault\n  * CVE-2019-11715 (bmo#1555523)\n    HTML parsing error can contribute to content XSS\n  * CVE-2019-11717 (bmo#1548306)\n    Caret character improperly escaped in origins\n  * CVE-2019-11719 (bmo#1540541)\n    Out-of-bounds read when importing curve25519 private key\n  * CVE-2019-11730 (bmo#1558299)\n    Same-origin policy treats all files in a directory as having the\n    same-origin\n  * CVE-2019-11709 (bmo#1547266, bmo#1540759, bmo#1548822, bmo#1550498\n    bmo#1515052, bmo#1539219, bmo#1547757, bmo#1550498, bmo#1533522)\n    Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 and\n    Thunderbird 60.8\n","affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Package Hub 12","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Package%20Hub%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"60.8.0-88.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"60.8.0-88.1","MozillaThunderbird-buildsymbols":"60.8.0-88.1","MozillaThunderbird-translations-common":"60.8.0-88.1","MozillaThunderbird-translations-other":"60.8.0-88.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:1990-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IM3PWUII7AODRR5RC2OP6EBPMKQT446V/#IM3PWUII7AODRR5RC2OP6EBPMKQT446V"},{"type":"REPORT","url":"https://bugzilla.suse.com/1137970"},{"type":"REPORT","url":"https://bugzilla.suse.com/1140868"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11709"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11711"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11712"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11713"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11715"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11717"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11719"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11729"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11730"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9811"}]}