SUSE-SU-2022:1176-1
Dashboard / Vulnerabilities / SUSE-SU-2022:1176-1
SUSE-SU-2022:1176-1
Summary: Security update for MozillaThunderbird
Details: This update for MozillaThunderbird fixes the following issues: - Updated to version 91.8 (bsc#1197903): - CVE-2022-1097: Fixed a memory corruption issue with NSSToken objects. - CVE-2022-28281: Fixed a memory corruption issue due to unexpected WebAuthN Extensions. - CVE-2022-1197: Fixed an issue where OpenPGP revocation information was ignored. - CVE-2022-1196: Fixed a memory corruption issue after VR process destruction. - CVE-2022-28282: Fixed a memory corruption issue in document translation. - CVE-2022-28285: Fixed a memory corruption issue in JIT code generation. - CVE-2022-28286: Fixed an iframe layout issue that could have been exploited to stage spoofing attacks. - CVE-2022-24713: Fixed a potential denial of service via complex regular expressions. - CVE-2022-28289: Fixed multiple memory corruption issues. Non-security fixes: - Changed Google accounts using password authentication to use OAuth2. - Fixed an issue where OpenPGP ECC keys created by Thunderbird could not be imported into GnuPG. - Fixed an issue where exporting multiple public PGP keys from Thunderbird was not possible. - Fixed an issue where replying to a newsgroup message erroneously displayed a 'No-reply' popup warning. - Fixed an issue with opening older address books. - Fixed an issue where LDAP directories would be lost when switching to 'Offline' mode. - Fixed an issue when importing webcals.
References: https://www.suse.com/support/update/announcement/2022/suse-su-20221176-1/, https://bugzilla.suse.com/1197903, https://www.suse.com/security/cve/CVE-2022-1097, https://www.suse.com/security/cve/CVE-2022-1196, https://www.suse.com/security/cve/CVE-2022-1197, https://www.suse.com/security/cve/CVE-2022-24713, https://www.suse.com/security/cve/CVE-2022-28281, https://www.suse.com/security/cve/CVE-2022-28282, https://www.suse.com/security/cve/CVE-2022-28285, https://www.suse.com/security/cve/CVE-2022-28286, https://www.suse.com/security/cve/CVE-2022-28289
Affected packages
Package
Name: MozillaThunderbird
Purl: pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
