## This update for MozillaThunderbird fixes the following issues: Security fixes: \- CVE-2023-5217: Fixed a heap buffer overflow in libvpx. (bsc#1215814) \- CVE-2023-5168: Out-of-bounds write in FilterNodeD2D1. (bsc#1215575) \- CVE-2023-5169: Out-of-bounds write in PathOps. (bsc#1215575) \- CVE-2023-5171: Use-after-free in Ion Compiler. (bsc#1215575) \- CVE-2023-5174: Double-free in process spawning on Windows. (bsc#1215575) \- CVE-2023-5176: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. (bsc#1215575) Other fixes: * Mozilla Thunderbird 115.3.1 * fixed: In Unified Folders view, some folders had incorrect unified folder parent (bmo#1852525) * fixed: "Edit message as new" did not restore encrypted subject from selected message (bmo#1788534)
* #1210168
* #1215309
* #1215575
* #1215814
Cross-
* CVE-2023-5168
* CVE-2023-5169
* CVE-2023-5171
* CVE-2023-5174
* CVE-2023-5176
* CVE-2023-5217
CVSS scores:
* CVE-2023-5168 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-5169 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2023-5171 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2023-5174 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-5176 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-5217 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-5217 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.4
* openSUSE Leap 15.5
* SUSE Linux Enterprise Desktop 15 SP4
Get the latest Linux and open source security news straight to your inbox.