{"schema_version":"1.7.3","id":"openSUSE-SU-2019:1162-1","published":"2019-04-05T10:09:15Z","modified":"2026-02-04T03:46:51.476386Z","related":["CVE-2018-18335","CVE-2018-18356","CVE-2018-18506","CVE-2018-18509","CVE-2019-5785","CVE-2019-9788","CVE-2019-9790","CVE-2019-9791","CVE-2019-9792","CVE-2019-9793","CVE-2019-9794","CVE-2019-9795","CVE-2019-9796","CVE-2019-9801","CVE-2019-9810","CVE-2019-9813"],"upstream":["CVE-2018-18335","CVE-2018-18356","CVE-2018-18506","CVE-2018-18509","CVE-2019-5785","CVE-2019-9788","CVE-2019-9790","CVE-2019-9791","CVE-2019-9792","CVE-2019-9793","CVE-2019-9794","CVE-2019-9795","CVE-2019-9796","CVE-2019-9801","CVE-2019-9810","CVE-2019-9813"],"summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird to version 60.5.1 fixes the following issues:\n\nSecurity issues fixed:\n\n- Update to MozillaThunderbird 60.6.1 (bsc#1130262):\n\n- CVE-2019-9813: Fixed Ionmonkey type confusion with __proto__ mutations\n- CVE-2019-9810: Fixed IonMonkey MArraySlice incorrect alias information\n\n- Update to MozillaThunderbird 60.6 (bsc#1129821):\n\n- CVE-2018-18506: Fixed an issue with Proxy Auto-Configuration file \n- CVE-2019-9801: Fixed an issue which could allow Windows programs to be exposed to web content\n- CVE-2019-9788: Fixed multiple memory safety bugs\n- CVE-2019-9790: Fixed a Use-after-free vulnerability when removing in-use DOM elements\n- CVE-2019-9791: Fixed an incorrect Type inference for constructors entered through on-stack replacement \n  with IonMonkey\n- CVE-2019-9792: Fixed an issue where IonMonkey leaks JS_OPTIMIZED_OUT magic value to script\n- CVE-2019-9793: Fixed multiple improper bounds checks when Spectre mitigations are disabled\n- CVE-2019-9794: Fixed an issue where command line arguments not discarded during execution\n- CVE-2019-9795: Fixed a Type-confusion vulnerability in IonMonkey JIT compiler\n- CVE-2019-9796: Fixed a Use-after-free vulnerability in SMIL animation controller\n\n- Update to MozillaThunderbird 60.5.1 (bsc#1125330):\n\n- CVE-2018-18356: Fixed a use-after-free vulnerability in the Skia library which can occur when\n    creating a path, leading to a potentially exploitable crash.\n- CVE-2019-5785: Fixed an integer overflow vulnerability in the Skia library which can occur\n  after specific transform operations, leading to a potentially exploitable crash.\n- CVE-2018-18335: Fixed a buffer overflow vulnerability in the Skia library which can occur with\n  Canvas 2D acceleration on macOS. This issue was addressed by disabling Canvas 2D acceleration \n  in Firefox ESR.  Note: this does not affect other versions and platforms where Canvas 2D\n  acceleration is already disabled by default.\n- CVE-2018-18509: Fixed a flaw which during verification of certain S/MIME signatures\n  showing mistakenly that emails bring a valid sugnature.\nRelease notes:\nhttps://www.mozilla.org/en-US/security/advisories/mfsa2019-12/\nhttps://www.mozilla.org/en-US/security/advisories/mfsa2019-11/\nhttps://www.mozilla.org/en-US/security/advisories/mfsa2019-06/\n","affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.0","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"60.6.1-lp150.3.37.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"60.6.1-lp150.3.37.1","MozillaThunderbird-buildsymbols":"60.6.1-lp150.3.37.1","MozillaThunderbird-translations-common":"60.6.1-lp150.3.37.1","MozillaThunderbird-translations-other":"60.6.1-lp150.3.37.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:1162-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AL5AUD2CY37ZNSQZPBX6C3K32ZVWBIIH/#AL5AUD2CY37ZNSQZPBX6C3K32ZVWBIIH"},{"type":"REPORT","url":"https://bugzilla.suse.com/1125330"},{"type":"REPORT","url":"https://bugzilla.suse.com/1129821"},{"type":"REPORT","url":"https://bugzilla.suse.com/1130262"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-18335"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-18356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-18506"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-18509"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5785"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9788"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9790"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9791"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9792"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9793"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9794"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9795"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9796"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9801"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9810"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9813"}]}