[MFSA-2022-54] Security Vulnerabilities fixed in Thunderbird 102.6.1
Severity
High
Affected Packages
1
Fixed Packages
1
CVEs
1
In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
- CVE-2022-46874: Drag and Dropped Filenames could have been truncated to malicious extensions (moderate) A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.<br/>Note: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted, resulting in it actually being fixed in Thunderbird 102.6.1
Package | Affected Version |
---|---|
pkg:mozilla/Thunderbird | < 102.6.1 |
Package | Fixed Version |
---|---|
pkg:mozilla/Thunderbird | = 102.6.1 |
- ID
- MFSA-2022-54
- Severity
- high
- URL
- https://www.mozilla.org/en-US/security/advisories/mfsa2022-54
- Published
-
2022-12-20T00:00:00
(21 months ago) - Modified
-
2022-12-20T00:00:00
(21 months ago) - Other Advisories
-
- ALAS2-2023-1951
- ALPINE:CVE-2022-46874
- ALSA-2022:9065
- ALSA-2022:9067
- ALSA-2022:9074
- ALSA-2022:9080
- DSA-5301-1
- DSA-5303-1
- ELSA-2022-9065
- ELSA-2022-9067
- ELSA-2022-9072
- ELSA-2022-9074
- ELSA-2022-9079
- ELSA-2022-9080
- GLSA-202305-06
- GLSA-202305-13
- MFSA-2022-51
- MFSA-2022-52
- RHSA-2022:9065
- RHSA-2022:9067
- RHSA-2022:9072
- RHSA-2022:9074
- RHSA-2022:9079
- RHSA-2022:9080
- RLSA-2022:9067
- SSA:2022-348-01
- SSA:2022-348-02
- SSA:2022-355-01
- SUSE-SU-2022:4460-1
- SUSE-SU-2022:4461-1
- SUSE-SU-2022:4462-1
- SUSE-SU-2022:4579-1
- SUSE-SU-2022:4636-1
- USN-5782-1
- USN-5824-1
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 1746139 | https://bugzilla.mozilla.org/show_bug.cgi?id=1746139 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:mozilla/Thunderbird | Thunderbird | < 102.6.1 | ||||
Fixed | pkg:mozilla/Thunderbird | Thunderbird | = 102.6.1 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |