SciLinux: SLSA-2019-1310-1 Important: thunderbird on SL6.x i386/x86_64
Summary
Important: thunderbird security update
Security Fixes
* Mozilla: Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7
(CVE-2019-9800)
* Mozilla: Cross-origin theft of images with createImageBitmap
(CVE-2019-9797)
* Mozilla: Stealing of cross-domain images using canvas (CVE-2019-9817)
* Mozilla: Compartment mismatch with fetch API (CVE-2019-9819)
* Mozilla: Use-after-free of ChromeEventHandler by DocShell (CVE-2019-9820)
* Mozilla: Use-after-free in XMLHttpRequest (CVE-2019-11691)
* Mozilla: Use-after-free removing listeners in the event listener manager
(CVE-2019-11692)
* Mozilla: Buffer overflow in WebGL bufferdata on Linux (CVE-2019-11693)
* mozilla: Cross-origin theft of images with ImageBitmapRenderingContext
(CVE-2018-18511)
* chromium-browser: Out of bounds read in Skia (CVE-2019-5798)
* Mozilla: Theft of user history data through drag and drop of hyperlinks
to and from bookmarks (CVE-2019-11698)
* libpng: use-after-free in png_image_free in png.c (CVE-2019-7317)
SL6
x86_64
thunderbird-60.7.0-1.el6_10.x86_64.rpm
thunderbird-debuginfo-60.7.0-1.el6_10.x86_64.rpm
i386
thunderbird-60.7.0-1.el6_10.i686.rpm
thunderbird-debuginfo-60.7.0-1.el6_10.i686.rpm
- Scientific Linux Development Team