This update for MozillaThunderbird fixes the following issues:
Security fixes:
* Mozilla Thunderbird 115.2.2 (MFSA 2023-40, bsc#1215245)
* CVE-2023-4863: Fixed heap buffer overflow in libwebp (bmo#1852649).
* Mozilla Thunderbird 115.2 (MFSA 2023-38, bsc#1214606)
* CVE-2023-4573: Memory corruption in IPC CanvasTranslator (bmo#1846687)
* CVE-2023-4574: Memory corruption in IPC ColorPickerShownCallback
(bmo#1846688)
* CVE-2023-4575: Memory corruption in IPC FilePickerShownCallback
(bmo#1846689)
* CVE-2023-4576: Integer Overflow in RecordedSourceSurfaceCreation
(bmo#1846694)
* CVE-2023-4577: Memory corruption in JIT UpdateRegExpStatics (bmo#1847397)
* CVE-2023-4051: Full screen notification obscured by file open dialog
(bmo#1821884)
* CVE-2023-4578: Error reporting methods in SpiderMonkey could have triggered
an Out of Memory Exception (bmo#1839007)
* CVE-2023-4053: Full screen notification obscured by external program
(bmo#1839079)
*...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Workstation Extension 15 SP5
zypper in -t patch SUSE-SLE-Product-WE-15-SP5-2023-3664=1
* openSUSE Leap 15.4
zypper in -t patch openSUSE-SLE-15.4-2023-3664=1
* openSUSE Leap 15.5
zypper in -t patch openSUSE-SLE-15.5-2023-3664=1
* SUSE Package Hub 15 15-SP4
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2023-3664=1
* SUSE Package Hub 15 15-SP5
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-3664=1
* SUSE Linux Enterprise Workstation Extension 15 SP4
zypper in -t patch SUSE-SLE-Product-WE-15-SP4-2023-3664=1
* SUSE Linux Enterprise Workstation Extension 15 SP5 (x86_64)
* MozillaThunderbird-debuginfo-115.2.2-150200.8.130.1
* MozillaThunderbird-translations-common-115.2.2-150200.8.130.1
* MozillaThunderbird-115.2.2-150200.8.130.1
* MozillaThunderbird-debugsource-115.2.2-150200.8.130.1
* MozillaThunderbird-translations-other-115.2.2-150200.8.130.1
* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)
* MozillaThunderbird-debuginfo-115.2.2-150200.8.130.1
* MozillaThunderbird-translations-common-115.2.2-150200.8.130.1
* MozillaThunderbird-115.2.2-150200.8.130.1
* MozillaThunderbird-debugsource-115.2.2-150200.8.130.1
* MozillaThunderbird-translations-other-115.2.2-150200.8.130.1
* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)
* MozillaThunderbird-debuginfo-115.2.2-150200.8.130.1
* MozillaThunderbird-translations-common-115.2.2-150200.8.130.1
* MozillaThunderbird-115.2.2-150200.8.130.1
* MozillaThunderbird-debugsource-115.2.2-150200.8.130.1
* MozillaThunderbird-translations-other-115.2.2-150200.8.130.1
* SUSE...
Read the Full Advisory* #1214606
* #1215231
* #1215245
## References:
* https://www.suse.com/security/cve/CVE-2023-4051.html
* https://www.suse.com/security/cve/CVE-2023-4053.html
* https://www.suse.com/security/cve/CVE-2023-4573.html
* https://www.suse.com/security/cve/CVE-2023-4574.html
* https://www.suse.com/security/cve/CVE-2023-4575.html
* https://www.suse.com/security/cve/CVE-2023-4576.html
* https://www.suse.com/security/cve/CVE-2023-4577.html
* https://www.suse.com/security/cve/CVE-2023-4578.html
* https://www.suse.com/security/cve/CVE-2023-4580.html
* https://www.suse.com/security/cve/CVE-2023-4581.html
* https://www.suse.com/security/cve/CVE-2023-4582.html
* https://www.suse.com/security/cve/CVE-2023-4583.html
* https://www.suse.com/security/cve/CVE-2023-4584.html
* https://www.suse.com/security/cve/CVE-2023-4585.html
* https://www.suse.com/security/cve/CVE-2023-4863.html
* https://bugzilla.suse.com/show_bug.cgi?id=1214606
* https://bugzilla.suse.com/show_bug.cgi?id=1215231
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.