Upstream information

CVE-2017-7846 at MITRE

Description

It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having important severity.

SUSE Bugzilla entry: 1074043 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Workstation Extension 15
  • MozillaThunderbird >= 52.8-1.2
  • MozillaThunderbird-devel >= 52.8-1.2
  • MozillaThunderbird-translations-common >= 52.8-1.2
  • MozillaThunderbird-translations-other >= 52.8-1.2
Patchnames:
SUSE Linux Enterprise Workstation Extension 15 GA MozillaThunderbird
SUSE Package Hub for SUSE Linux Enterprise 12
  • MozillaThunderbird >= 52.5.2-51.1
  • MozillaThunderbird-buildsymbols >= 52.5.2-51.1
  • MozillaThunderbird-debuginfo >= 52.5.2-51.1
  • MozillaThunderbird-debugsource >= 52.5.2-51.1
  • MozillaThunderbird-devel >= 52.5.2-51.1
  • MozillaThunderbird-translations-common >= 52.5.2-51.1
  • MozillaThunderbird-translations-other >= 52.5.2-51.1
Patchnames:
openSUSE-2017-1419
openSUSE Leap 15.0
  • MozillaThunderbird >= 52.7-lp150.2.16
  • MozillaThunderbird-translations-common >= 52.7-lp150.2.16
  • MozillaThunderbird-translations-other >= 52.7-lp150.2.16
Patchnames:
openSUSE Leap 15.0 GA MozillaThunderbird
openSUSE Leap 42.2
  • MozillaThunderbird >= 52.5.2-41.24.1
  • MozillaThunderbird-buildsymbols >= 52.5.2-41.24.1
  • MozillaThunderbird-debuginfo >= 52.5.2-41.24.1
  • MozillaThunderbird-debugsource >= 52.5.2-41.24.1
  • MozillaThunderbird-devel >= 52.5.2-41.24.1
  • MozillaThunderbird-translations-common >= 52.5.2-41.24.1
  • MozillaThunderbird-translations-other >= 52.5.2-41.24.1
Patchnames:
openSUSE-2017-1419
openSUSE Leap 42.3
  • MozillaThunderbird >= 52.5.2-53.1
  • MozillaThunderbird-buildsymbols >= 52.5.2-53.1
  • MozillaThunderbird-debuginfo >= 52.5.2-53.1
  • MozillaThunderbird-debugsource >= 52.5.2-53.1
  • MozillaThunderbird-devel >= 52.5.2-53.1
  • MozillaThunderbird-translations-common >= 52.5.2-53.1
  • MozillaThunderbird-translations-other >= 52.5.2-53.1
Patchnames:
openSUSE-2017-1419