Bug 1074043 - (CVE-2017-7846) VUL-0: CVE-2017-7846: MozillaThunderbird: JavaScript Execution via RSS in mailbox:// origin
(CVE-2017-7846)
VUL-0: CVE-2017-7846: MozillaThunderbird: JavaScript Execution via RSS in mai...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 42.3
Other Other
: P3 - Medium : Major (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/197240/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-12-23 21:30 UTC by Andreas Stieger
Modified: 2019-02-19 07:07 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2017-12-23 21:30:41 UTC
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via “View -> Feed article -> Website” or in the standard format of “View -> Feed article -> default format”.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7846
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7846
https://bugzilla.mozilla.org/show_bug.cgi?id=1411716
https://www.mozilla.org/en-US/security/advisories/mfsa2017-30/#CVE-2017-7846
Comment 1 Swamp Workflow Management 2017-12-23 22:50:06 UTC
This is an autogenerated message for OBS integration:
This bug (1074043) was mentioned in
https://build.opensuse.org/request/show/559659 42.2+42.3+Backports:SLE-12 / MozillaThunderbird
Comment 2 Andreas Stieger 2017-12-24 08:34:35 UTC
submitted
Comment 3 Andreas Stieger 2017-12-24 22:29:31 UTC
done
Comment 4 Swamp Workflow Management 2017-12-25 02:07:21 UTC
openSUSE-SU-2017:3433-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1074043,1074044,1074045,1074046
CVE References: CVE-2017-7829,CVE-2017-7846,CVE-2017-7847,CVE-2017-7848
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    MozillaThunderbird-52.5.2-51.1
Comment 5 Swamp Workflow Management 2017-12-25 02:07:58 UTC
openSUSE-SU-2017:3434-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1074043,1074044,1074045,1074046
CVE References: CVE-2017-7829,CVE-2017-7846,CVE-2017-7847,CVE-2017-7848
Sources used:
openSUSE Leap 42.3 (src):    MozillaThunderbird-52.5.2-53.1
openSUSE Leap 42.2 (src):    MozillaThunderbird-52.5.2-41.24.1
Comment 7 Swamp Workflow Management 2018-03-24 10:20:06 UTC
This is an autogenerated message for OBS integration:
This bug (1074043) was mentioned in
https://build.opensuse.org/request/show/590813 42.3 / MozillaThunderbird