Security update for Mozilla Thunderbird
This update to Thunderbird 52.2 fixes security issues and bugs. The following vulnerabilities were fixed: * CVE-2017-5472: Use-after-free using destroyed node when regenerating trees * CVE-2017-7749: Use-after-free during docshell reloading * CVE-2017-7750: Use-after-free with track elements * CVE-2017-7751: Use-after-free with content viewer listeners * CVE-2017-7752: Use-after-free with IME input * CVE-2017-7754: Out-of-bounds read in WebGL with ImageInfo object * CVE-2017-7756: Use-after-free and use-after-scope logging XHR header errors * CVE-2017-7757: Use-after-free in IndexedDB * CVE-2017-7778, CVE-2017-7778, CVE-2017-7771, CVE-2017-7772, CVE-2017-7773, CVE-2017-7774, CVE-2017-7775, CVE-2017-7776, CVE-2017-7777: Vulnerabilities in the Graphite 2 library * CVE-2017-7758: Out-of-bounds read in Opus encoder * CVE-2017-7764: Domain spoofing with combination of Canadian Syllabics and other unicode blocks * CVE-2017-5470: Memory safety bugs fixed in Firefox 54 and Firefox ESR 52.2 Mozilla Thunderbird now requires NSS 3.28.5. The following bugs were fixed: * Embedded images not shown in email received from Hotmail/Outlook webmailer * Detection of non-ASCII font names in font selector * Attachment not forwarded correctly under certain circumstances * Multiple requests for master password when GMail OAuth2 is enabled * Large number of blank pages being printed under certain circumstances when invalid preferences were present * Messages sent via the Simple MAPI interface are forced to HTML * Calendar: Invitations can't be printed * Mailing list (group) not accessible from macOS or Outlook address book * Clicking on links with references/anchors where target doesn't exist in the message not opening in external browser
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update to Thunderbird 52.2 fixes security issues and bugs. The following vulnerabilities were fixed: * CVE-2017-5472: Use-after-free using destroyed node when regenerating trees * CVE-2017-7749: Use-after-free during docshell reloading * CVE-2017-7750: Use-after-free with track elements * CVE-2017-7751: Use-after-free with content viewer listeners * CVE-2017-7752: Use-after-free with IME input * CVE-2017-7754: Out-of-bounds read in WebGL with ImageInfo object * CVE-2017-7756: Use-after-free and use-after-scope logging XHR header errors * CVE-2017-7757: Use-after-free in IndexedDB * CVE-2017-7778, CVE-2017-7778, CVE-2017-7771, CVE-2017-7772, CVE-2017-7773, CVE-2017-7774, CVE-2017-7775, CVE-2017-7776, CVE-2017-7777: Vulnerabilities in the Graphite 2 library * CVE-2017-7758: Out-of-bounds read in Opus encoder * CVE-2017-7764: Domain spoofing with combination of Canadian Syllabics and other unicode blocks * CVE-2017-5470: Memory safety bugs fixed in Firefox 54 and Firefox ESR 52.2 Mozilla Thunderbird now requires NSS 3.28.5. The following bugs were fixed: * Embedded images not shown in email received from Hotmail/Outlook webmailer * Detection of non-ASCII font names in font selector * Attachment not forwarded correctly under certain circumstances * Multiple requests for master password when GMail OAuth2 is enabled * Large number of blank pages being printed under certain circumstances when invalid preferences were present * Messages sent via the Simple MAPI interface are forced to HTML * Calendar: Invitations can't be printed * Mailing list (group) not accessible from macOS or Outlook address book * Clicking on links with references/anchors where target doesn't exist in the message not opening in external browser
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1040105
- https://bugzilla.suse.com/1042090
- https://bugzilla.suse.com/1043960
- https://bugzilla.suse.com/1273265
- https://bugzilla.suse.com/1355039
- https://bugzilla.suse.com/1356558
- https://bugzilla.suse.com/1356824
- https://bugzilla.suse.com/1357090
- https://bugzilla.suse.com/1359547
- https://bugzilla.suse.com/1360309
- https://bugzilla.suse.com/1363396
- https://bugzilla.suse.com/1364283
- https://bugzilla.suse.com/1365602
- https://bugzilla.suse.com/1366595
- https://bugzilla.suse.com/1368490
- https://www.suse.com/security/cve/CVE-2017-5470
- https://www.suse.com/security/cve/CVE-2017-5472
- https://www.suse.com/security/cve/CVE-2017-7749
- https://www.suse.com/security/cve/CVE-2017-7750
- https://www.suse.com/security/cve/CVE-2017-7751
- https://www.suse.com/security/cve/CVE-2017-7752
- https://www.suse.com/security/cve/CVE-2017-7754
- https://www.suse.com/security/cve/CVE-2017-7756
- https://www.suse.com/security/cve/CVE-2017-7757
- https://www.suse.com/security/cve/CVE-2017-7758
- https://www.suse.com/security/cve/CVE-2017-7763
- https://www.suse.com/security/cve/CVE-2017-7764
- https://www.suse.com/security/cve/CVE-2017-7765
- https://www.suse.com/security/cve/CVE-2017-7771
- https://www.suse.com/security/cve/CVE-2017-7772
- https://www.suse.com/security/cve/CVE-2017-7773
- https://www.suse.com/security/cve/CVE-2017-7774
- https://www.suse.com/security/cve/CVE-2017-7775
- https://www.suse.com/security/cve/CVE-2017-7776
- https://www.suse.com/security/cve/CVE-2017-7777
- https://www.suse.com/security/cve/CVE-2017-7778