[openSUSE-SU-2021:0387-1] Security update for MozillaThunderbird
Severity
Important
Affected Packages
3
CVEs
4
Security update for MozillaThunderbird
This update for MozillaThunderbird fixes the following issues:
- Mozilla Thunderbird 78.8
- fixed: Importing an address book from a CSV file always reported an error
- fixed: Security information for S/MIME messages was not displayed correctly prior to a draft being saved
- fixed: Calendar: FileLink UI fixes for Caldav calendars
- fixed: Recurring tasks were always marked incomplete; unable to use filters
- fixed: Various UI widgets not working
- fixed: Dark theme improvements
- fixed: Extension manager was missing link to addon support web page
- fixed: Various security fixes MFSA 2021-09 (bsc#1182614)
- CVE-2021-23969: Content Security Policy violation report could have contained the destination of a redirect
- CVE-2021-23968: Content Security Policy violation report could have contained the destination of a redirect
- CVE-2021-23973: MediaError message property could have leaked information about cross-origin resources
- CVE-2021-23978: Memory safety bugs fixed in Thunderbird 78.8
This update was imported from the SUSE:SLE-15-SP2:Update update project.
Package | Affected Version |
---|---|
pkg:rpm/opensuse/MozillaThunderbird?arch=x86_64&distro=opensuse-leap-15.2 | < 78.8.0-lp152.2.35.1 |
pkg:rpm/opensuse/MozillaThunderbird-translations-other?arch=x86_64&distro=opensuse-leap-15.2 | < 78.8.0-lp152.2.35.1 |
pkg:rpm/opensuse/MozillaThunderbird-translations-common?arch=x86_64&distro=opensuse-leap-15.2 | < 78.8.0-lp152.2.35.1 |
- ID
- openSUSE-SU-2021:0387-1
- Severity
- important
- URL
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2REQ3DSH3BKY3CWSHN3VOQE3JTXUFINV/
- Published
-
2021-03-05T22:42:16
(3 years ago) - Modified
-
2021-03-05T22:42:16
(3 years ago) - Rights
- Copyright 2024 SUSE LLC. All rights reserved.
- Other Advisories
-
- ALAS2-2021-1618
- ALPINE:CVE-2021-23968
- ALPINE:CVE-2021-23969
- ALPINE:CVE-2021-23973
- ALPINE:CVE-2021-23978
- ALSA-2021:0655
- ALSA-2021:0657
- DSA-4862-1
- DSA-4866-1
- ELSA-2021-0655
- ELSA-2021-0656
- ELSA-2021-0657
- ELSA-2021-0661
- GLSA-202104-09
- GLSA-202104-10
- MFSA-2021-07
- MFSA-2021-08
- MFSA-2021-09
- openSUSE-SU-2021:0373-1
- RHSA-2021:0655
- RHSA-2021:0656
- RHSA-2021:0657
- RHSA-2021:0661
- SUSE-SU-2021:0659-1
- SUSE-SU-2021:0661-1
- SUSE-SU-2021:0667-1
- SUSE-SU-2021:0676-1
- USN-4756-1
- USN-4936-1
Source | # ID | Name | URL |
---|---|---|---|
Suse | SUSE ratings | https://www.suse.com/support/security/rating/ | |
Suse | URL of this CSAF notice | https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2021_0387-1.json | |
Suse | URL for openSUSE-SU-2021:0387-1 | https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2REQ3DSH3BKY3CWSHN3VOQE3JTXUFINV/ | |
Suse | E-Mail link for openSUSE-SU-2021:0387-1 | https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2REQ3DSH3BKY3CWSHN3VOQE3JTXUFINV/ | |
Bugzilla | SUSE Bug 1182357 | https://bugzilla.suse.com/1182357 | |
Bugzilla | SUSE Bug 1182614 | https://bugzilla.suse.com/1182614 | |
CVE | SUSE CVE CVE-2021-23968 page | https://www.suse.com/security/cve/CVE-2021-23968/ | |
CVE | SUSE CVE CVE-2021-23969 page | https://www.suse.com/security/cve/CVE-2021-23969/ | |
CVE | SUSE CVE CVE-2021-23973 page | https://www.suse.com/security/cve/CVE-2021-23973/ | |
CVE | SUSE CVE CVE-2021-23978 page | https://www.suse.com/security/cve/CVE-2021-23978/ |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/opensuse/MozillaThunderbird?arch=x86_64&distro=opensuse-leap-15.2 | opensuse | MozillaThunderbird | < 78.8.0-lp152.2.35.1 | opensuse-leap-15.2 | x86_64 | |
Affected | pkg:rpm/opensuse/MozillaThunderbird-translations-other?arch=x86_64&distro=opensuse-leap-15.2 | opensuse | MozillaThunderbird-translations-other | < 78.8.0-lp152.2.35.1 | opensuse-leap-15.2 | x86_64 | |
Affected | pkg:rpm/opensuse/MozillaThunderbird-translations-common?arch=x86_64&distro=opensuse-leap-15.2 | opensuse | MozillaThunderbird-translations-common | < 78.8.0-lp152.2.35.1 | opensuse-leap-15.2 | x86_64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |