[MFSA-2022-43] Security Vulnerabilities fixed in Thunderbird 102.3.1

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 4
  • CVE-2022-39236: Matrix SDK bundled with Thunderbird vulnerable to a data corruption issue (moderate)
    Thunderbird users who use the Matrix chat protocol were vulnerable to a data corruption issue. An adversary could potentially cause data integrity issues by sending specially crafted messages.

  • CVE-2022-39249: Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack by malicious server administrators (high)
    Thunderbird users who use the Matrix chat protocol were vulnerable to an impersonation attack. A malicious server administrator could fake encrypted messages to look as if they were sent from another user on that server.

  • CVE-2022-39250: Matrix SDK bundled with Thunderbird vulnerable to a device verification attack (high)
    Thunderbird users who use the Matrix chat protocol were vulnerable to an impersonation attack. A malicious server administrator could interfere with cross-device verification to authenticate their own device.

  • CVE-2022-39251: Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack (high)
    Thunderbird users who use the Matrix chat protocol were vulnerable to an impersonation attack. An adversary could spoof historical messages from other users. Additionally, a malicious key backup to the user's account under certain unusual conditions in order to exfiltrate message keys.

Package Affected Version
pkg:mozilla/Thunderbird < 102.3.1
Package Fixed Version
pkg:mozilla/Thunderbird = 102.3.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:mozilla/Thunderbird Thunderbird < 102.3.1
Fixed pkg:mozilla/Thunderbird Thunderbird = 102.3.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...