Security update for Mozilla Thunderbird
This update for Mozilla Thunderbird to version 52.5.2 fixes the following vulnerabilities: - CVE-2017-7846: JavaScript Execution via RSS in mailbox:// origin (bsc#1074043) - CVE-2017-7847: Local path string can be leaked from RSS feed (bsc#1074044) - CVE-2017-7848: RSS Feed vulnerable to new line Injection (bsc#1074045) - CVE-2017-7829: From address with encoded null character is cut off in message header display (bsc#1074046)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for Mozilla Thunderbird to version 52.5.2 fixes the following vulnerabilities: - CVE-2017-7846: JavaScript Execution via RSS in mailbox:// origin (bsc#1074043) - CVE-2017-7847: Local path string can be leaked from RSS feed (bsc#1074044) - CVE-2017-7848: RSS Feed vulnerable to new line Injection (bsc#1074045) - CVE-2017-7829: From address with encoded null character is cut off in message header display (bsc#1074046)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1074043
- https://bugzilla.suse.com/1074044
- https://bugzilla.suse.com/1074045
- https://bugzilla.suse.com/1074046
- https://lists.opensuse.org/archives/list/[email protected]/thread/Y37ZBDTQYH6U74CLMVTFTTZQHZYSKJPC/#Y37ZBDTQYH6U74CLMVTFTTZQHZYSKJPC
- https://www.suse.com/security/cve/CVE-2017-7829
- https://www.suse.com/security/cve/CVE-2017-7846
- https://www.suse.com/security/cve/CVE-2017-7847
- https://www.suse.com/security/cve/CVE-2017-7848