Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia: 2022-0428 Moderate: Thunderbird Cross-Origin Issues Fixed

mageia
Calendar Grey November 17, 2022
Dist Mageia Esm H88
Mageia has issued new advisory updates to address severe security flaws in Thunderbird. Delve into the specifics.
Service Workers might have learned size of cross-origin media files

Summary

Service Workers might have learned size of cross-origin media files. (CVE-2022-45403)
Fullscreen notification bypass. (CVE-2022-45404)
Use-after-free in InputStream implementation. (CVE-2022-45405)
Use-after-free of a JavaScript Realm. (CVE-2022-45406)
Fullscreen notification bypass via windowName. (CVE-2022-45408)
Use-after-free in Garbage Collection. (CVE-2022-45409)
ServiceWorker-intercepted requests bypassed SameSite cookie policy. (CVE-2022-45410)
Cross-Site Tracing was possible via non-standard override headers. (CVE-2022-45411)
Symlinks may resolve to partially uninitialized buffers. (CVE-2022-45412)
Keystroke Side-Channel Leakage. (CVE-2022-45416)
Custom mouse cursor could have been drawn over browser UI. (CVE-2022-45418)
Iframe contents could be rendered outside the iframe. (CVE-2022-45420)
Memory safety bugs fixed in Thunderbird 102.5. (CVE-2022-45421)

References

- https://bugs.mageia.org/show_bug.cgi?id=31131

- https://www.thunderbird.net/en-US/thunderbird/102.5.0/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2022-49/

- https://www.cve.org/CVERecord?id=CVE-2022-45403

- https://www.cve.org/CVERecord?id=CVE-2022-45404

- https://www.cve.org/CVERecord?id=CVE-2022-45405

- https://www.cve.org/CVERecord?id=CVE-2022-45406

- https://www.cve.org/CVERecord?id=CVE-2022-45408

- https://www.cve.org/CVERecord?id=CVE-2022-45409

- https://www.cve.org/CVERecord?id=CVE-2022-45410

- https://www.cve.org/CVERecord?id=CVE-2022-45411

- https://www.cve.org/CVERecord?id=CVE-2022-45412

- https://www.cve.org/CVERecord?id=CVE-2022-45416

- https://www.cve.org/CVERecord?id=CVE-2022-45418

- https://www.cve.org/CVERecord?id=CVE-2022-45420

- https://www.cve.org/CVERecord?id=CVE-2022-45421

Resolution

SRPMS

- 8/core/thunderbird-102.5.0-1.mga8

- 8/core/thunderbird-l10n-102.5.0-1.mga8

Publication date: 17 Nov 2022
URL: https://advisories.mageia.org/MGASA-2022-0428.html
Type: security
CVE: CVE-2022-45403, CVE-2022-45404, CVE-2022-45405, CVE-2022-45406, CVE-2022-45408, CVE-2022-45409, CVE-2022-45410, CVE-2022-45411, CVE-2022-45412, CVE-2022-45416, CVE-2022-45418, CVE-2022-45420, CVE-2022-45421

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here