openSUSE-SU-2021:1854-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:1854-1
openSUSE-SU-2021:1854-1
Summary: Security update for MozillaThunderbird
Details: This update for MozillaThunderbird fixes the following issues: - Mozilla Thunderbird 78.10.2 - CVE-2021-29957: Fixed partial protection of inline OpenPGP message not indicated (bsc#1186198). - CVE-2021-29956: Fixed Thunderbird stored OpenPGP secret keys without master password protection (bsc#1186199). - CVE-2021-29951: Fixed Thunderbird Maintenance Service could have been started or stopped by domain users (bsc#1185633). - CVE-2021-29950: Fixed logic issue potentially leaves key material unlocked (bsc#1185086).
References: https://lists.opensuse.org/archives/list/[email protected]/thread/7FGBREHMZI3UK2I6TGJZ75S4VSJHXVNF/, https://bugzilla.suse.com/1185086, https://bugzilla.suse.com/1185633, https://bugzilla.suse.com/1186198, https://bugzilla.suse.com/1186199, https://www.suse.com/security/cve/CVE-2021-29950, https://www.suse.com/security/cve/CVE-2021-29951, https://www.suse.com/security/cve/CVE-2021-29956, https://www.suse.com/security/cve/CVE-2021-29957
Affected packages
Package
Name: MozillaThunderbird
Purl: pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
