[MFSA-2022-31] Security Vulnerabilities fixed in Thunderbird 91.12

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 2

In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.

  • CVE-2022-36318: Directory indexes for bundled resources reflected URL parameters (moderate)
    When visiting directory listings for chrome:// URLs as source text, some parameters were reflected.

  • CVE-2022-36319: Mouse Position spoofing with CSS transforms (moderate)
    When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed.

Package Affected Version
pkg:mozilla/Thunderbird < 91.12
Package Fixed Version
pkg:mozilla/Thunderbird = 91.12
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:mozilla/Thunderbird Thunderbird < 91.12
Fixed pkg:mozilla/Thunderbird Thunderbird = 91.12
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date