Improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly(CVE-2022-39236) Too permissive key forwarding strategy allowing impersonation (CVE-2022-39249) Trusting/verifying the user identity under the control of the homeserver . MGASA-2022-0355 - Updated thunderbird packages fix security vulnerability Publication date: 01 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0355.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-39236, CVE-2022-39249, CVE-2022-39250, CVE-2022-39251 Improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly(CVE-2022-39236) Too permissive key forwarding strategy allowing impersonation (CVE-2022-39249) Trusting/verifying the user identity under the control of the homeserver instead of the intended one. (CVE-2022-39250) Fake to-device messages appearing to originate from another user. (CVE-2022-39251) References: - https://bugs.mageia.org/show_bug.cgi?id=30911 - https://www.mozilla.org/en-US/security/advisories/mfsa2022-43/ - https://www.thunderbird.net/en-US/thunderbird/102.3.1/releasenotes/ - https://www.cve.org/CVERecord?id=CVE-2022-39236 - https://www.cve.org/CVERecord?id=CVE-2022-39249 - https://www.cve.org/CVERecord?id=CVE-2022-39250 - https://www.cve.org/CVERecord?id=CVE-2022-39251 SRPMS: - 8/core/thunderbird-102.3.1-1.mga8 - 8/core/thunderbird-l10n-102.3.1-1.mga8 . Mageia 2022-0458 rolls out a security patch for Firefox, addressing severe flaws, released on 05 Nov 2022. Mageia Security Advisory, Thunderbird Update, Identity Verification, Key Forwarding Threat, Software Update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.