SUSE-SU-2023:3059-1

    Dashboard / Vulnerabilities / SUSE-SU-2023:3059-1

    SUSE-SU-2023:3059-1

    Published: 31 Jul 2023Last Modified: 4 Feb 2026

    Summary: Security update for MozillaThunderbird

    Details: This update for MozillaThunderbird fixes the following issues: Mozilla Thunderbird was updated to version 115.0.1 (bsc#1212438): - CVE-2023-3600: Fixed use-after-free in workers (bmo#1839703). - CVE-2023-3417: Fixed File Extension Spoofing using the Text Direction Override Character (bmo#1835582). Bugfixes: - changed: Added Thunderbird Supernova branding to about:dialog (bmo#1842102) - fixed: Message list was not updated when message was deleted from server outside of Thunderbird (bmo#1837041) - fixed: Scrolling behaved unexpectedly when moving to next message unread message in another folder (bmo#1841711) - fixed: Scrolling animation was unnecessarily used when switching or toggling the sort column in message list (bmo#1838522) - fixed: Attempting to delete a message and then cancelling the action still marked the message as read (bmo#793353) - fixed: Unified Toolbar could not be customized under certain tabs (bmo#1841480) - fixed: Selecting a folder with one or more subfolders and pressing enter did not expand folder (bmo#1841200) - fixed: Tooltips did not appear when hovering over folders (bmo#1839780) - fixed: Deleting large amounts of messages from Trash folder consumed excessive time and memory (bmo#1833665) - fixed: Message Summary header buttons were not keyboard accessible (bmo#1827199) - fixed: 'New' button in Message Filters dialog was not keyboard accessible (bmo#1841477) - fixed: Backing up secret keys from OpenPGP Key Manager dialog silently failed (bmo#1839415) - fixed: Various visual and UX improvements (bmo#1843172,bmo#1831422,bmo#1838360,bmo#1842319)

    Affected packages

    Package

    Name: MozillaThunderbird

    Purl: pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -115.0.1-150200.8.124.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2023:3059-1 | CVE-DB