Bug 1160305 - VUL-0: MozillaFirefox, MozillaThunderbird: Update Firefox and Thunderbird to 72.0/68.4 esr (MFSA 2020-01 and MFSA 2020-02)
VUL-0: MozillaFirefox, MozillaThunderbird: Update Firefox and Thunderbird to ...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-01-07 14:41 UTC by Martin Sirringhaus
Modified: 2022-09-06 16:42 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Martin Sirringhaus 2020-01-07 14:41:22 UTC
CVE-2019-17015: (bmo#1599005) Memory corruption in parent process during new content process initialization on Windows
CVE-2019-17016: (bmo#1599181) Bypass of @namespace CSS sanitization during pasting
CVE-2019-17017: (bmo#1603055) Type Confusion in XPCVariant.cpp
CVE-2019-17021: (bmo#1599008) Heap address disclosure in parent process during content process initialization on Windows
CVE-2019-17022: (bmo#1602843) CSS sanitization does not escape HTML tags
CVE-2019-17024: (bmo#1507180, bmo#1595470, bmo#1598605, bmo#1601826) Memory safety bugs fixed in Firefox 72 and Firefox ESR 68.4
Comment 1 Charles Robertson 2020-01-08 22:23:51 UTC
  * CVE-2019-17018 (bmo#1549394)
    Windows Keyboard in Private Browsing Mode may retain word
    suggestions
  * CVE-2019-17019 (bmo#1568003)
    Python files could be inadvertently executed upon opening a
    download
  * CVE-2019-17020 (bmo#1597645)
    Content Security Policy not applied to XSL stylesheets
    applied to XML documents
  * CVE-2019-17023 (bmo#1590001)
    NSS may negotiate TLS 1.2 or below after a TLS 1.3
    HelloRetryRequest had been sent
  * CVE-2019-17025 (bmo#1328295, bmo#1328300, bmo#1590447,
    bmo#1590965, bmo#1595692, bmo#1597321, bmo#1597481)
    Memory safety bugs fixed in Firefox 72
Comment 2 Swamp Workflow Management 2020-01-09 08:10:33 UTC
This is an autogenerated message for OBS integration:
This bug (1160305) was mentioned in
https://build.opensuse.org/request/show/762071 Factory / MozillaFirefox
Comment 5 Swamp Workflow Management 2020-01-10 14:14:24 UTC
SUSE-SU-2020:0068-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1160305,1160498
CVE References: CVE-2019-17015,CVE-2019-17016,CVE-2019-17017,CVE-2019-17021,CVE-2019-17022,CVE-2019-17024,CVE-2019-17026
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE OpenStack Cloud 8 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE OpenStack Cloud 7 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP5 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP4 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Desktop 12-SP4 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Enterprise Storage 5 (src):    MozillaFirefox-68.4.1-109.101.1
HPE Helion Openstack 8 (src):    MozillaFirefox-68.4.1-109.101.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2020-01-10 17:14:07 UTC
SUSE-SU-2020:14268-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1160305,1160498
CVE References: CVE-2019-17015,CVE-2019-17016,CVE-2019-17017,CVE-2019-17021,CVE-2019-17022,CVE-2019-17024,CVE-2019-17026
Sources used:
SUSE Linux Enterprise Server 11-SP4-LTSS (src):    MozillaFirefox-68.4.1-78.57.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2020-01-11 09:20:05 UTC
This is an autogenerated message for OBS integration:
This bug (1160305) was mentioned in
https://build.opensuse.org/request/show/763056 Factory / MozillaThunderbird
Comment 9 Swamp Workflow Management 2020-01-13 14:15:29 UTC
SUSE-SU-2020:0078-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1160305,1160498
CVE References: CVE-2019-17015,CVE-2019-17016,CVE-2019-17017,CVE-2019-17021,CVE-2019-17022,CVE-2019-17024,CVE-2019-17026
Sources used:
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src):    MozillaFirefox-68.4.1-3.66.1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    MozillaFirefox-68.4.1-3.66.1
SUSE Linux Enterprise Module for Desktop Applications 15-SP1 (src):    MozillaFirefox-68.4.1-3.66.1
SUSE Linux Enterprise Module for Desktop Applications 15 (src):    MozillaFirefox-68.4.1-3.66.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2020-01-15 14:11:23 UTC
openSUSE-SU-2020:0060-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1160305,1160498
CVE References: CVE-2019-17015,CVE-2019-17016,CVE-2019-17017,CVE-2019-17021,CVE-2019-17022,CVE-2019-17024,CVE-2019-17026
Sources used:
openSUSE Leap 15.1 (src):    MozillaFirefox-68.4.1-lp151.2.24.1
Comment 11 Swamp Workflow Management 2020-01-20 20:14:12 UTC
SUSE-SU-2020:0142-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1160305,1160498
CVE References: CVE-2019-17015,CVE-2019-17016,CVE-2019-17017,CVE-2019-17021,CVE-2019-17022,CVE-2019-17024,CVE-2019-17026
Sources used:
SUSE Linux Enterprise Workstation Extension 15-SP1 (src):    MozillaThunderbird-68.4.1-3.66.1
SUSE Linux Enterprise Workstation Extension 15 (src):    MozillaThunderbird-68.4.1-3.66.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Swamp Workflow Management 2020-01-22 17:12:38 UTC
openSUSE-SU-2020:0094-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1160305,1160498
CVE References: CVE-2019-17015,CVE-2019-17016,CVE-2019-17017,CVE-2019-17021,CVE-2019-17022,CVE-2019-17024,CVE-2019-17026
Sources used:
openSUSE Leap 15.1 (src):    MozillaThunderbird-68.4.1-lp151.2.22.2
Comment 13 Marcus Meissner 2020-02-05 07:45:51 UTC
done