1
0
MozillaThunderbird/thunderbird-68.6.0.source.tar.xz.asc
Wolfgang Rosenauer 56310e4a94 - Mozilla Thunderbird 68.6.0
MFSA 2020-10 (bsc#1166238)
  * CVE-2020-6805 (bmo#1610880)
    Use-after-free when removing data about origins
  * CVE-2020-6806 (bmo#1612308)
    BodyStream::OnInputStreamReady was missing protections against
    state confusion
  * CVE-2020-6807 (bmo#1614971)
    Use-after-free in cubeb during stream destruction
  * CVE-2020-6811 (bmo#1607742)
    Devtools' 'Copy as cURL' feature did not fully escape
    website-controlled data, potentially leading to command injection
  * CVE-2019-20503 (bmo#1613765)
    Out of bounds reads in sctp_load_addresses_from_init
  * CVE-2020-6812 (bmo#1616661)
    The names of AirPods with personally identifiable information
    were exposed to websites with camera or microphone permission
  * CVE-2020-6814 (bmo#1592078, bmo#1604847, bmo#1608256, bmo#1612636,
    bmo#1614339)
    Memory safety bugs fixed in Thunderbird 68.6
- requires NSS >= 3.44.3

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=522
2020-03-14 13:26:42 +00:00

17 lines
833 B
Plaintext

-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEECXsxMHeuYqAvhNpN8aZmj7t9Vy4FAl5oAY8ACgkQ8aZmj7t9
Vy4asQ/+PcLQFYT/fLT4zY4aBkzo4pULKtjXD7bL10rnHGBqo73XZRKfAh/A35Uz
derK7MMfkebF1loM3XOHOFFOtcaRDgiK8+gC62llip3oOICZlK0Vj3T4EiqtrE9Q
4QfLwfghbSaNKHYz8zUBBlWA8YHI7lcH5y+4U31D3R1ObWTGDabJFNDnJ4cchUVO
DpBoFxPs62f/BSe2MoSHZty/9p2XHw+ReNN/IA1sTVpuHAxnk+z9DmlYsGDSJ06b
6eb253dafSyRf/djQbeKruLIwisQc4JHbewL5Vu5bqlEDTR+a32g7eK8S/6EU4qn
xH5SuL4NPvfUy/4QQ9hd4hAmGE249kWstoLY4CwYsHa9kEGgTFztmGdRjqJ5XzjL
k9j/ZnDEu4TiLsrgTVesOIintSuAfSS4jl/BY3tZo0W5h9WyrhfiM7Ax3G3CVMRu
a2lzCRD6uY8R7KvV/KVu7ofE/ZOrh+XG+WGyRrNxLvHxiPAqIKEWZjsG18EulMd/
mT/fXRbKA/vd1Ma0z7yszQDxBwhEW2R8v416YO56kegeCu37Lt/H2Y7CLZOXnzEy
cNqK2GuzVOOSNW/uqJfnLhXK+SlaApVukK2/UV9qfr7g3F6i6wlSJRWLz3Fl2BSW
LANBCkCaKdH5JN8zdZEEwXMRFY9S/lVKmIkfhXZoKFsR/y3QJS8=
=m6Zj
-----END PGP SIGNATURE-----