File _patchinfo of Package patchinfo.10428

<patchinfo incident="10428">
  <issue tracker="bnc" id="1137595">VUL-0: CVE-2019-11703,CVE-2019-11704,CVE-2019-11705,CVE-2019-11706: MozillaThunderbird: multiple vulnerabilities</issue>
  <issue tracker="cve" id="2019-11704"/>
  <issue tracker="cve" id="2019-11705"/>
  <issue tracker="cve" id="2019-11706"/>
  <issue tracker="cve" id="2019-11703"/>
  <category>security</category>
  <rating>important</rating>
  <packager>wrosenauer</packager>
  <description>This update for MozillaThunderbird fixes the following issues:

Mozilla Thunderbird was updated to 60.7.1:

Security issues fixed with MFSA 2019-17 (boo#1137595)

- CVE-2019-11703: Fixed a heap-based buffer overflow in icalmemorystrdupanddequote() (bsc#1137595).
- CVE-2019-11704: Fixed a heap-based buffer overflow in parser_get_next_char() (bsc#1137595).
- CVE-2019-11705: Fixed a stack-based buffer overflow in icalrecur_add_bydayrules() (bsc#1137595).
- CVE-2019-11706: Fixed a type confusion in icaltimezone_get_vtimezone_properties() (bsc#1137595).

Also fixed:
- No prompt for smartcard PIN when S/MIME signing is used
</description>
  <summary>Security update for MozillaThunderbird</summary>
</patchinfo>
openSUSE Build Service is sponsored by