openSUSE_Evergreen_Maintenance_4651 Security update for Mozilla Thunderbird important openSUSE 13.1 Update ports This update contains Mozilla Thunderbird 45.2. (boo#983549) It fixes security issues mostly affecting the e-mail program when used in a browser context, such as viewing a web page or HTMl formatted e-mail. The following vulnerabilities were fixed: - CVE-2016-2818, CVE-2016-2815: Memory safety bugs (boo#983549, MFSA2016-49) Contains the following security fixes from the 45.1 release: (boo#977333) - CVE-2016-2806, CVE-2016-2807: Miscellaneous memory safety hazards (boo#977375, boo#977376, MFSA 2016-39) Contains the following security fixes from the 45.0 release: (boo#969894) - CVE-2016-1952, CVE-2016-1953: Miscellaneous memory safety hazards (MFSA 2016-16) - CVE-2016-1954: Local file overwriting and potential privilege escalation through CSP reports (MFSA 2016-17) - CVE-2016-1955: CSP reports fail to strip location information for embedded iframe pages (MFSA 2016-18) - CVE-2016-1956: Linux video memory DOS with Intel drivers (MFSA 2016-19) - CVE-2016-1957: Memory leak in libstagefright when deleting an array during MP4 processing (MFSA 2016-20) - CVE-2016-1960: Use-after-free in HTML5 string parser (MFSA 2016-23) - CVE-2016-1961: Use-after-free in SetBody (MFSA 2016-24) - CVE-2016-1964: Use-after-free during XML transformations (MFSA 2016-27) - CVE-2016-1974: Out-of-bounds read in HTML parser following a failed allocation (MFSA 2016-34) The graphite font shaping library was disabled, addressing the following font vulnerabilities: - MFSA 2016-37/CVE-2016-1977/CVE-2016-2790/CVE-2016-2791/ CVE-2016-2792/CVE-2016-2793/CVE-2016-2794/CVE-2016-2795/ CVE-2016-2796/CVE-2016-2797/CVE-2016-2798/CVE-2016-2799/ CVE-2016-2800/CVE-2016-2801/CVE-2016-2802 The following tracked packaging changes are included: - fix build issues with gcc/binutils combination used in Leap 42.2 (boo#984637) - gcc6 fixes (boo#986162) - running on 48bit va aarch64 (boo#984126) MozillaThunderbird-45.2-70.83.1.armv7hl.rpm MozillaThunderbird-45.2-70.83.1.src.rpm MozillaThunderbird-debuginfo-45.2-70.83.1.armv7hl.rpm MozillaThunderbird-debugsource-45.2-70.83.1.armv7hl.rpm MozillaThunderbird-devel-45.2-70.83.1.armv7hl.rpm MozillaThunderbird-translations-common-45.2-70.83.1.armv7hl.rpm MozillaThunderbird-translations-other-45.2-70.83.1.armv7hl.rpm MozillaThunderbird-45.2-70.83.1.ppc64.rpm MozillaThunderbird-debuginfo-45.2-70.83.1.ppc64.rpm MozillaThunderbird-debugsource-45.2-70.83.1.ppc64.rpm MozillaThunderbird-devel-45.2-70.83.1.ppc64.rpm MozillaThunderbird-translations-common-45.2-70.83.1.ppc64.rpm MozillaThunderbird-translations-other-45.2-70.83.1.ppc64.rpm