{"schema_version":"1.7.3","id":"openSUSE-SU-2020:0643-1","published":"2020-05-09T22:21:15Z","modified":"2025-05-07T18:11:22.220499Z","related":["CVE-2020-12387","CVE-2020-12392","CVE-2020-12393","CVE-2020-12395","CVE-2020-12397","CVE-2020-6831"],"upstream":["CVE-2020-12387","CVE-2020-12392","CVE-2020-12393","CVE-2020-12395","CVE-2020-12397","CVE-2020-6831"],"summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n- Update to 68.8.0 ESR\n  MFSA 2020-18 (bsc#1171186)\n  * CVE-2020-12397 (bmo#1617370)\n    Sender Email Address Spoofing using encoded Unicode\n    characters\n  * CVE-2020-12387 (bmo#1545345)\n    Use-after-free during worker shutdown\n  * CVE-2020-6831 (bmo#1632241)\n    Buffer overflow in SCTP chunk input validation\n  * CVE-2020-12392 (bmo#1614468)\n    Arbitrary local file access with 'Copy as cURL'\n  * CVE-2020-12393 (bmo#1615471)\n    Devtools' 'Copy as cURL' feature did not fully escape\n    website-controlled data, potentially leading to command\n    injection\n  * CVE-2020-12395 (bmo#1595886, bmo#1611482, bmo#1614704,\n    bmo#1624098, bmo#1625749, bmo#1626382, bmo#1628076,\n    bmo#1631508)\n    Memory safety bugs fixed in Thunderbird 68.8.0\n\n\nThis update was imported from the SUSE:SLE-15:Update update project.","affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"68.8.0-lp151.2.38.2"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"68.8.0-lp151.2.38.2","MozillaThunderbird-translations-common":"68.8.0-lp151.2.38.2","MozillaThunderbird-translations-other":"68.8.0-lp151.2.38.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0643-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5YQSDU3MFHQWYW5DLTHJ4JOYHWTHCHMN/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1171186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-12387"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-12392"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-12393"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-12395"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-12397"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6831"}]}