Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 8: MGASA-2022-0484 Moderate: Malicious Extensions in Thunderbird

mageia
Calendar Grey December 30, 2022
Dist Mageia Esm H88
Revamped Thunderbird versions tackle vulnerability concerns surrounding harmful file extensions, announced on January 12, 2023.
Drag and Dropped Filenames could have been truncated to malicious extensions

Summary

Drag and Dropped Filenames could have been truncated to malicious extensions. (CVE-2022-46874)

References

- https://bugs.mageia.org/show_bug.cgi?id=31307

- https://www.thunderbird.net/en-US/thunderbird/102.6.1/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2022-54/

- https://www.cve.org/CVERecord?id=CVE-2022-46874

Resolution

SRPMS

- 8/core/thunderbird-102.6.1-1.mga8

- 8/core/thunderbird-l10n-102.6.1-1.mga8

Publication date: 30 Dec 2022
URL: https://advisories.mageia.org/MGASA-2022-0484.html
Type: security
CVE: CVE-2022-46874

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here