|
|
Subscribe / Log in / New account

Scientific Linux alert SLSA-2019:1777-1 (thunderbird)

From:  Farhan Ahmed <fahmed@fnal.gov>
To:  <scientific-linux-errata@listserv.fnal.gov>
Subject:  Security ERRATA Important: thunderbird on SL6.x i386/x86_64
Date:  Mon, 15 Jul 2019 17:34:45 +0000
Message-ID:  <20190715173445.1900.24053@slpackages.fnal.gov>

Synopsis: Important: thunderbird security update Advisory ID: SLSA-2019:1777-1 Issue Date: 2019-07-15 CVE Numbers: CVE-2019-11709 CVE-2019-11711 CVE-2019-11712 CVE-2019-11713 CVE-2019-11715 CVE-2019-11717 CVE-2019-11730 CVE-2019-9811 -- This update upgrades Thunderbird to version 60.8.0. Security Fix(es): * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects (CVE-2019-11712) * Mozilla: Use-after-free with HTTP/2 cached stream (CVE-2019-11713) * Mozilla: HTML parsing error can contribute to content XSS (CVE-2019-11715) * Mozilla: Caret character improperly escaped in origins (CVE-2019-11717) * Mozilla: Same-origin policy treats all files in a directory as having the same-origin (CVE-2019-11730) -- SL6 x86_64 thunderbird-60.8.0-1.el6_10.x86_64.rpm thunderbird-debuginfo-60.8.0-1.el6_10.x86_64.rpm i386 thunderbird-60.8.0-1.el6_10.i686.rpm thunderbird-debuginfo-60.8.0-1.el6_10.i686.rpm - Scientific Linux Development Team


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds