Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 8: 2022-0163 Moderate: Thunderbird Email Notification Issues

mageia
Calendar Grey May 6, 2022
Dist Mageia Esm H88
Firefox security patches tackle numerous vulnerabilities, such as access violations and misleading alerts for notifications.
Incorrect security status shown after viewing an attached email

Summary

Incorrect security status shown after viewing an attached email. (CVE-2022-1520) Fullscreen notification bypass using popups. (CVE-2022-29914) Bypassing permission prompt in nested browsing contexts. (CVE-2022-29909) Leaking browser history with CSS variables. (CVE-2022-29916) iframe sandbox bypass. (CVE-2022-29911) Reader mode bypassed SameSite cookies. (CVE-2022-29912) Speech Synthesis feature not properly disabled. (CVE-2022-29913) Memory safety bugs fixed in Thunderbird 91.9. (CVE-2022-29917)

References

- https://bugs.mageia.org/show_bug.cgi?id=30374

- https://www.mozilla.org/en-US/security/advisories/mfsa2022-18/

- https://www.thunderbird.net/en-US/thunderbird/91.9.0/releasenotes/

- https://www.cve.org/CVERecord?id=CVE-2022-1520

- https://www.cve.org/CVERecord?id=CVE-2022-29909

- https://www.cve.org/CVERecord?id=CVE-2022-29911

- https://www.cve.org/CVERecord?id=CVE-2022-29912

- https://www.cve.org/CVERecord?id=CVE-2022-29913

- https://www.cve.org/CVERecord?id=CVE-2022-29914

- https://www.cve.org/CVERecord?id=CVE-2022-29916

- https://www.cve.org/CVERecord?id=CVE-2022-29917

Resolution

SRPMS

- 8/core/thunderbird-91.9.0-1.mga8

- 8/core/thunderbird-l10n-91.9.0-1.mga8

Publication date: 06 May 2022
URL: https://advisories.mageia.org/MGASA-2022-0163.html
Type: security
CVE: CVE-2022-1520, CVE-2022-29909, CVE-2022-29911, CVE-2022-29912, CVE-2022-29913, CVE-2022-29914, CVE-2022-29916, CVE-2022-29917

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here