[SUSE-SU-2022:2320-1] Security update for MozillaThunderbird

Severity Important
Affected Packages 24
CVEs 10

Security update for MozillaThunderbird

This update for MozillaThunderbird fixes the following issues:

  • CVE-2022-2200: Undesired attributes could be set as part of prototype pollution (bmo#1771381)
  • CVE-2022-2226: An email with a mismatching OpenPGP signature date was accepted as valid (bmo#1775441)
  • CVE-2022-31744: CSP bypass enabling stylesheet injection (bmo#1757604)
  • CVE-2022-34468: CSP sandbox header without allow-scripts can be bypassed via retargeted javascript: URI (bmo#1768537)
  • CVE-2022-34470: Use-after-free in nsSHistory (bmo#1765951)
  • CVE-2022-34472: Unavailable PAC file resulted in OCSP requests being blocked (bmo#1770123)
  • CVE-2022-34478: Microsoft protocols can be attacked if a user accepts a prompt (bmo#1773717)
  • CVE-2022-34479: A popup window could be resized in a way to overlay the address bar with web content (bmo#1745595)
  • CVE-2022-34481: Potential integer overflow in ReplaceElementsAt (bmo#1497246)
  • CVE-2022-34484: Memory safety bugs fixed in Thunderbird 91.11 and Thunderbird 102 (bmo#1763634, bmo#1772651)
Package Affected Version
pkg:rpm/suse/MozillaThunderbird?arch=x86_64&distro=opensuse-leap-15.4 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird?arch=x86_64&distro=opensuse-leap-15.3 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird?arch=s390x&distro=opensuse-leap-15.4 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird?arch=s390x&distro=opensuse-leap-15.3 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird?arch=ppc64le&distro=opensuse-leap-15.4 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird?arch=ppc64le&distro=opensuse-leap-15.3 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird?arch=aarch64&distro=opensuse-leap-15.4 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird?arch=aarch64&distro=opensuse-leap-15.3 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-other?arch=x86_64&distro=opensuse-leap-15.4 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-other?arch=x86_64&distro=opensuse-leap-15.3 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-other?arch=s390x&distro=opensuse-leap-15.4 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-other?arch=s390x&distro=opensuse-leap-15.3 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-other?arch=ppc64le&distro=opensuse-leap-15.4 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-other?arch=ppc64le&distro=opensuse-leap-15.3 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-other?arch=aarch64&distro=opensuse-leap-15.4 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-other?arch=aarch64&distro=opensuse-leap-15.3 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-common?arch=x86_64&distro=opensuse-leap-15.4 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-common?arch=x86_64&distro=opensuse-leap-15.3 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-common?arch=s390x&distro=opensuse-leap-15.4 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-common?arch=s390x&distro=opensuse-leap-15.3 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-common?arch=ppc64le&distro=opensuse-leap-15.4 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-common?arch=ppc64le&distro=opensuse-leap-15.3 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-common?arch=aarch64&distro=opensuse-leap-15.4 < 91.11.0-150200.8.76.1
pkg:rpm/suse/MozillaThunderbird-translations-common?arch=aarch64&distro=opensuse-leap-15.3 < 91.11.0-150200.8.76.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/MozillaThunderbird?arch=x86_64&distro=opensuse-leap-15.4 suse MozillaThunderbird < 91.11.0-150200.8.76.1 opensuse-leap-15.4 x86_64
Affected pkg:rpm/suse/MozillaThunderbird?arch=x86_64&distro=opensuse-leap-15.3 suse MozillaThunderbird < 91.11.0-150200.8.76.1 opensuse-leap-15.3 x86_64
Affected pkg:rpm/suse/MozillaThunderbird?arch=s390x&distro=opensuse-leap-15.4 suse MozillaThunderbird < 91.11.0-150200.8.76.1 opensuse-leap-15.4 s390x
Affected pkg:rpm/suse/MozillaThunderbird?arch=s390x&distro=opensuse-leap-15.3 suse MozillaThunderbird < 91.11.0-150200.8.76.1 opensuse-leap-15.3 s390x
Affected pkg:rpm/suse/MozillaThunderbird?arch=ppc64le&distro=opensuse-leap-15.4 suse MozillaThunderbird < 91.11.0-150200.8.76.1 opensuse-leap-15.4 ppc64le
Affected pkg:rpm/suse/MozillaThunderbird?arch=ppc64le&distro=opensuse-leap-15.3 suse MozillaThunderbird < 91.11.0-150200.8.76.1 opensuse-leap-15.3 ppc64le
Affected pkg:rpm/suse/MozillaThunderbird?arch=aarch64&distro=opensuse-leap-15.4 suse MozillaThunderbird < 91.11.0-150200.8.76.1 opensuse-leap-15.4 aarch64
Affected pkg:rpm/suse/MozillaThunderbird?arch=aarch64&distro=opensuse-leap-15.3 suse MozillaThunderbird < 91.11.0-150200.8.76.1 opensuse-leap-15.3 aarch64
Affected pkg:rpm/suse/MozillaThunderbird-translations-other?arch=x86_64&distro=opensuse-leap-15.4 suse MozillaThunderbird-translations-other < 91.11.0-150200.8.76.1 opensuse-leap-15.4 x86_64
Affected pkg:rpm/suse/MozillaThunderbird-translations-other?arch=x86_64&distro=opensuse-leap-15.3 suse MozillaThunderbird-translations-other < 91.11.0-150200.8.76.1 opensuse-leap-15.3 x86_64
Affected pkg:rpm/suse/MozillaThunderbird-translations-other?arch=s390x&distro=opensuse-leap-15.4 suse MozillaThunderbird-translations-other < 91.11.0-150200.8.76.1 opensuse-leap-15.4 s390x
Affected pkg:rpm/suse/MozillaThunderbird-translations-other?arch=s390x&distro=opensuse-leap-15.3 suse MozillaThunderbird-translations-other < 91.11.0-150200.8.76.1 opensuse-leap-15.3 s390x
Affected pkg:rpm/suse/MozillaThunderbird-translations-other?arch=ppc64le&distro=opensuse-leap-15.4 suse MozillaThunderbird-translations-other < 91.11.0-150200.8.76.1 opensuse-leap-15.4 ppc64le
Affected pkg:rpm/suse/MozillaThunderbird-translations-other?arch=ppc64le&distro=opensuse-leap-15.3 suse MozillaThunderbird-translations-other < 91.11.0-150200.8.76.1 opensuse-leap-15.3 ppc64le
Affected pkg:rpm/suse/MozillaThunderbird-translations-other?arch=aarch64&distro=opensuse-leap-15.4 suse MozillaThunderbird-translations-other < 91.11.0-150200.8.76.1 opensuse-leap-15.4 aarch64
Affected pkg:rpm/suse/MozillaThunderbird-translations-other?arch=aarch64&distro=opensuse-leap-15.3 suse MozillaThunderbird-translations-other < 91.11.0-150200.8.76.1 opensuse-leap-15.3 aarch64
Affected pkg:rpm/suse/MozillaThunderbird-translations-common?arch=x86_64&distro=opensuse-leap-15.4 suse MozillaThunderbird-translations-common < 91.11.0-150200.8.76.1 opensuse-leap-15.4 x86_64
Affected pkg:rpm/suse/MozillaThunderbird-translations-common?arch=x86_64&distro=opensuse-leap-15.3 suse MozillaThunderbird-translations-common < 91.11.0-150200.8.76.1 opensuse-leap-15.3 x86_64
Affected pkg:rpm/suse/MozillaThunderbird-translations-common?arch=s390x&distro=opensuse-leap-15.4 suse MozillaThunderbird-translations-common < 91.11.0-150200.8.76.1 opensuse-leap-15.4 s390x
Affected pkg:rpm/suse/MozillaThunderbird-translations-common?arch=s390x&distro=opensuse-leap-15.3 suse MozillaThunderbird-translations-common < 91.11.0-150200.8.76.1 opensuse-leap-15.3 s390x
Affected pkg:rpm/suse/MozillaThunderbird-translations-common?arch=ppc64le&distro=opensuse-leap-15.4 suse MozillaThunderbird-translations-common < 91.11.0-150200.8.76.1 opensuse-leap-15.4 ppc64le
Affected pkg:rpm/suse/MozillaThunderbird-translations-common?arch=ppc64le&distro=opensuse-leap-15.3 suse MozillaThunderbird-translations-common < 91.11.0-150200.8.76.1 opensuse-leap-15.3 ppc64le
Affected pkg:rpm/suse/MozillaThunderbird-translations-common?arch=aarch64&distro=opensuse-leap-15.4 suse MozillaThunderbird-translations-common < 91.11.0-150200.8.76.1 opensuse-leap-15.4 aarch64
Affected pkg:rpm/suse/MozillaThunderbird-translations-common?arch=aarch64&distro=opensuse-leap-15.3 suse MozillaThunderbird-translations-common < 91.11.0-150200.8.76.1 opensuse-leap-15.3 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...