Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

openSUSE: 2023:3059-1 important: MozillaThunderbird Update for Security

opensuse
Calendar Grey July 31, 2023
Scroller Opensuse
Investigate the latest patches addressing significant vulnerabilities in Mozilla Thunderbird within openSUSE ecosystems for improved security.
This update for MozillaThunderbird fixes the following issues: Mozilla Thunderbird was updated to version 115.0.1 (bsc#1212438):

Description

This update for MozillaThunderbird fixes the following issues:

Mozilla Thunderbird was updated to version 115.0.1 (bsc#1212438):

* CVE-2023-3600: Fixed use-after-free in workers (bmo#1839703).

* CVE-2023-3417: Fixed File Extension Spoofing using the Text Direction

Override Character (bmo#1835582).

Bugfixes:

* changed: Added Thunderbird Supernova branding to about:dialog (bmo#1842102)

* fixed: Message list was not updated when message was deleted from server

outside of Thunderbird (bmo#1837041)

* fixed: Scrolling behaved unexpectedly when moving to next message unread

message in another folder (bmo#1841711)

* fixed: Scrolling animation was unnecessarily used when switching or toggling

the sort column in message list (bmo#1838522)

* fixed: Attempting to delete a message and then cancelling the action still

marked the message as read (bmo#793353)

* fixed: Unified Toolbar could not be customized under certain tabs

(bmo#1841480)

* fixed:...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE Important update use the SUSE recommended installation

methods like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch openSUSE-SLE-15.4-2023-3059=1

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2023-3059=1

* SUSE Package Hub 15 15-SP4

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2023-3059=1

* SUSE Package Hub 15 15-SP5

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-3059=1

* SUSE Linux Enterprise Workstation Extension 15 SP4

zypper in -t patch SUSE-SLE-Product-WE-15-SP4-2023-3059=1

* SUSE Linux Enterprise Workstation Extension 15 SP5

zypper in -t patch SUSE-SLE-Product-WE-15-SP5-2023-3059=1

Package List

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)

* MozillaThunderbird-debugsource-115.0.1-150200.8.124.1

* MozillaThunderbird-debuginfo-115.0.1-150200.8.124.1

* MozillaThunderbird-translations-other-115.0.1-150200.8.124.1

* MozillaThunderbird-115.0.1-150200.8.124.1

* MozillaThunderbird-translations-common-115.0.1-150200.8.124.1

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)

* MozillaThunderbird-debugsource-115.0.1-150200.8.124.1

* MozillaThunderbird-debuginfo-115.0.1-150200.8.124.1

* MozillaThunderbird-translations-other-115.0.1-150200.8.124.1

* MozillaThunderbird-115.0.1-150200.8.124.1

* MozillaThunderbird-translations-common-115.0.1-150200.8.124.1

* SUSE Package Hub 15 15-SP4 (aarch64 ppc64le s390x)

* MozillaThunderbird-debugsource-115.0.1-150200.8.124.1

* MozillaThunderbird-debuginfo-115.0.1-150200.8.124.1

* MozillaThunderbird-translations-other-115.0.1-150200.8.124.1

* MozillaThunderbird-115.0.1-150200.8.124.1

* MozillaThunderbird-translations-common-115.0.1-150200.8.124.1

* SUSE Package...

Read the Full Advisory

References

* #1212438

## References:

* https://www.suse.com/security/cve/CVE-2023-3417.html

* https://www.suse.com/security/cve/CVE-2023-3600.html

* https://bugzilla.suse.com/show_bug.cgi?id=1212438

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:3059-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.