File _patchinfo of Package patchinfo.11423
<patchinfo incident="11423"> <issue tracker="bnc" id="1130694">rust 1.33.0 breaks Firefox and Thunderbird</issue> <issue tracker="bnc" id="1135824">VUL-0: MozillaFirefox: multiple vulnerabilities fixed on 67 (MFSA 2019-13) / 60.0.7 ESR (MFSA 2019-14)</issue> <issue tracker="bnc" id="1133267">LTO: MozillaThunderbird build fails</issue> <issue tracker="cve" id="2019-9800"/> <issue tracker="cve" id="2019-9818"/> <issue tracker="cve" id="2019-9819"/> <issue tracker="cve" id="2019-7317"/> <issue tracker="cve" id="2019-9815"/> <issue tracker="cve" id="2019-9816"/> <issue tracker="cve" id="2019-9817"/> <issue tracker="cve" id="2019-5798"/> <issue tracker="cve" id="2019-11694"/> <issue tracker="cve" id="2019-11692"/> <issue tracker="cve" id="2019-11693"/> <issue tracker="cve" id="2019-11691"/> <issue tracker="cve" id="2019-9797"/> <issue tracker="cve" id="2018-18511"/> <issue tracker="cve" id="2019-11698"/> <issue tracker="cve" id="2019-9820"/> <category>security</category> <rating>important</rating> <packager>msmeissn</packager> <description>This update for MozillaThunderbird fixes the following issues: Mozilla Thunderbird was updated to 60.7.0. * Attachment pane of Write window no longer focussed when attaching files using a keyboard shortcut These security issues were fixed (MFSA 2019-15 bsc#1135824): * CVE-2019-9815: Disable hyperthreading on content JavaScript threads on macOS * CVE-2019-9816: Type confusion with object groups and UnboxedObjects * CVE-2019-9817: Stealing of cross-domain images using canvas * CVE-2019-9818: Use-after-free in crash generation server * CVE-2019-9819: Compartment mismatch with fetch API * CVE-2019-9820: Use-after-free of ChromeEventHandler by DocShell * CVE-2019-11691: Use-after-free in XMLHttpRequest * CVE-2019-11692: Use-after-free removing listeners in the event listener manager * CVE-2019-11693: Buffer overflow in WebGL bufferdata on Linux * CVE-2019-7317: Use-after-free in png_image_free of libpng library * CVE-2019-9797: Cross-origin theft of images with createImageBitmap * CVE-2018-18511: Cross-origin theft of images with ImageBitmapRenderingContext * CVE-2019-11694: (Windows only) Uninitialized memory memory leakage in Windows sandbox * CVE-2019-11698: Theft of user history data through drag and drop of hyperlinks to and from bookmarks * CVE-2019-5798: Out-of-bounds read in Skia * CVE-2019-9800: Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7 </description> <summary>Security update for MozillaThunderbird</summary> </patchinfo>




