Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.856856
Kategorie:openSUSE Local Security Checks
Titel:openSUSE Security Advisory (SUSE-SU-2024:4326-1)
Zusammenfassung:The remote host is missing an update for the 'MozillaThunderbird' package(s) announced via the SUSE-SU-2024:4326-1 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'MozillaThunderbird' package(s) announced via the SUSE-SU-2024:4326-1 advisory.

Vulnerability Insight:
This update for MozillaThunderbird fixes the following issues:

- CVE-2024-50336: Fixed insufficient MXC URI validation which could allow client-side path traversal (bsc#1234413)

Other fixes:
- Updated to Mozilla Thunderbird 128.5.2i (bsc#1234413):
* fixed: Large virtual folders could be very slow
* fixed: Message could disappear after moving from IMAP folder
followed by Undo and Redo
* fixed: XMPP chat did not display messages sent inside a CDATA
element
* fixed: Selected calendar day did not move forward at midnight
* fixed: Today pane agenda sometimes scrolled for no apparent
reason
* fixed: CalDAV calendars without offline support could degrade
start-up performance
* fixed: Visual and UX improvements
* fixed: Security fixes

- Updated to Mozilla Thunderbird 128.5.1:
* new: Add end of year donation appeal
* fixed: Total message count for favorite folders did not work
consistently

Affected Software/OS:
'MozillaThunderbird' package(s) on openSUSE Leap 15.5, openSUSE Leap 15.6.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2024-50336
CopyrightCopyright (C) 2024 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.