Drag and Dropped Filenames could have been truncated to malicious extensions. (CVE-2022-46874) References: - https://bugs.mageia.org/show_bug.cgi?id=31307 . MGASA-2022-0484 - Updated thunderbird packages fix security vulnerability Publication date: 30 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0484.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-46874 Drag and Dropped Filenames could have been truncated to malicious extensions. (CVE-2022-46874) References: - https://bugs.mageia.org/show_bug.cgi?id=31307 - https://www.thunderbird.net/en-US/thunderbird/102.6.1/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2022-54/ - https://www.cve.org/CVERecord?id=CVE-2022-46874 SRPMS: - 8/core/thunderbird-102.6.1-1.mga8 - 8/core/thunderbird-l10n-102.6.1-1.mga8 . Revamped Thunderbird versions tackle vulnerability concerns surrounding harmful file extensions, announced on January 12, 2023.. Thunderbird Security, Mageia Advisory, Malicious Extensions, Security Update. . LinuxSecurity.com Team
Several security issues were fixed in Thunderbird.. =========================================================================Ubuntu Security Notice USN-4995-1 June 22, 2021 thunderbird vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.04 - Ubuntu 20.10 - Ubuntu 20.04 LTS Summary: Several security issues were fixed in Thunderbird. Software Description: - thunderbird: Mozilla Open Source mail and newsgroup client Details: Multiple security issues were discovered in Thunderbird. If a user were tricked into opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, spoof the UI, bypass security restrictions, or execute arbitrary code. (CVE-2021-23961, CVE-2021-23981, CVE-2021-23982, CVE-2021-23987, CVE-2021-23994, CVE-2021-23998, CVE-2021-23999, CVE-2021-29945, CVE-2021-29946, CVE-2021-29967) It was discovered that extensions could open popup windows with control of the window title in some circumstances. If a user were tricked into installing a specially crafted extension, an attacker could potentially exploit this to spoof a website and trick the user into providing credentials. (CVE-2021-23984) Multiple security issues were discovered in Thunderbird's OpenPGP integration. If a user were tricked into importing a specially crafted key in some circumstances, an attacker could potentially exploit this to cause a denial of service (inability to send encrypted email) or confuse the user. (CVE-2021-23991, CVE-2021-23992, CVE-2021-23993) A use-after-free was discovered when Responsive Design Mode was enabled. If a user were tricked into opening a specially crafted website with Responsive Design Mode enabled, an attacker could potentially exploit this to cause a denial of service, or execute arbitrary code. (CVE-2021-23995) It was discoveredthat Thunderbird mishandled ftp URLs with encoded newline characters. If a user were tricked into clicking on a specially crafted link, an attacker could potentially exploit this to send arbitrary FTP commands. (CVE-2021-24002) It was discovered that Thunderbird wrote signatures to disk and read them back during verification. A local attacker could potentially exploit this to replace the data with another signature file. (CVE-2021-29948) It was discovered that Thunderbird might load an alternative OTR library. If a user were tricked into copying a specially crafted library to one of Thunderbird's search paths, an attacker could potentially exploit this to execute arbitrary code. (CVE-2021-29949) It was discovered that secret keys imported into Thunderbird were stored unencrypted. A local attacker could potentially exploit this to obtain private keys. (CVE-2021-29956) It was discovered that Thunderbird did not indicate when an inline signed or encrypted message contained additional unprotected parts. (CVE-2021-29957) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: thunderbird 1:78.11.0+build1-0ubuntu0.21.04.2 Ubuntu 20.10: thunderbird 1:78.11.0+build1-0ubuntu0.20.10.2 Ubuntu 20.04 LTS: thunderbird 1:78.11.0+build1-0ubuntu0.20.04.2 After a standard system update you need to restart Thunderbird to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4995-1 CVE-2021-23961, CVE-2021-23981, CVE-2021-23982, CVE-2021-23984, CVE-2021-23987, CVE-2021-23991, CVE-2021-23992, CVE-2021-23993, CVE-2021-23994, CVE-2021-23995, CVE-2021-23998, CVE-2021-23999, CVE-2021-24002, CVE-2021-29945, CVE-2021-29946, CVE-2021-29948, CVE-2021-29949, CVE-2021-29956, CVE-2021-29957, CVE-2021-29967 PackageInformation: https://launchpad.net/ubuntu/+source/thunderbird/1:78.11.0+build1-0ubuntu0.21.04.2 https://launchpad.net/ubuntu/+source/thunderbird/1:78.11.0+build1-0ubuntu0.20.10.2 https://launchpad.net/ubuntu/+source/thunderbird/1:78.11.0+build1-0ubuntu0.20.04.2 . Multiple vulnerabilities addressed in Thunderbird for Ubuntu; features fixes for denial of service, remote code execution, and unauthorized data access.. Thunderbird Update, Ubuntu Security Notice, Open Source Email Client. . Severity: Important. LinuxSecurity.com Team
An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1007-1 Rating: important References: #1183942 Cross-References: CVE-2021-23981 CVE-2021-23982 CVE-2021-23984 CVE-2021-23987 Affected Products: SUSE MicroOS 5.0 SUSE Manager Server 4.0 SUSE Manager Retail Branch Server 4.0 SUSE Manager Proxy 4.0 SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server for SAP 15 SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise Module for Basesystem 15-SP2 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise High Performance Computing 15-ESPOS SUSE Enterprise Storage 6 SUSE CaaS Platform 4.0 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for MozillaFirefox fixes the following issues: - Firefox was updated to 78.9.0 ESR (MFSA 2021-11, bsc#1183942) * CVE-2021-23981: Texture upload into an unbound backing buffer resulted in an out-of-bound read * CVE-2021-23982: Internal network hosts could have been probed by a malicious webpage * CVE-2021-23984: Malicious extensions could have spoofed popup information * CVE-2021-23987: Memory safety bugs Patch Instructions: Toinstall this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE MicroOS 5.0: zypper in -t patch SUSE-SUSE-MicroOS-5.0-2021-1007=1 - SUSE Manager Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.0-2021-1007=1 - SUSE Manager Retail Branch Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.0-2021-1007=1 - SUSE Manager Proxy 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.0-2021-1007=1 - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2021-1007=1 - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2021-1007=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2021-1007=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2021-1007=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2021-1007=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-1007=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2021-1007=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2021-1007=1 - SUSE Linux Enterprise High Performance Computing 15-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-2021-1007=1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-2021-1007=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2021-1007=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaSPlatform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE MicroOS 5.0 (aarch64 x86_64): mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 - SUSE Manager Server 4.0 (ppc64le s390x x86_64): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Manager Server 4.0 (x86_64): mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 - SUSE Manager Retail Branch Server 4.0 (x86_64): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Manager Proxy 4.0 (x86_64): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (x86_64): mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 - SUSE Linux Enterprise Server for SAP 15 (ppc64le x86_64): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Linux Enterprise Server for SAP 15 (x86_64): mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (x86_64): mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Linux Enterprise Server 15-LTSS (aarch64 s390x): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (x86_64): mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (x86_64): mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (x86_64): mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64 x86_64): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (x86_64): mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64 x86_64): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (x86_64): mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 - SUSE Enterprise Storage 6 (x86_64): mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 - SUSE CaaS Platform 4.0 (x86_64): MozillaFirefox-78.9.0-3.136.1 MozillaFirefox-branding-SLE-78-4.16.1 MozillaFirefox-debuginfo-78.9.0-3.136.1 MozillaFirefox-debugsource-78.9.0-3.136.1 MozillaFirefox-devel-78.9.0-3.136.1 MozillaFirefox-translations-common-78.9.0-3.136.1 MozillaFirefox-translations-other-78.9.0-3.136.1 mozilla-nspr-32bit-4.25.1-3.17.1 mozilla-nspr-32bit-debuginfo-4.25.1-3.17.1 mozilla-nspr-4.25.1-3.17.1 mozilla-nspr-debuginfo-4.25.1-3.17.1 mozilla-nspr-debugsource-4.25.1-3.17.1 mozilla-nspr-devel-4.25.1-3.17.1 References: https://www.suse.com/security/cve/CVE-2021-23981.html https://www.suse.com/security/cve/CVE-2021-23982.html https://www.suse.com/security/cve/CVE-2021-23984.html https://www.suse.com/security/cve/CVE-2021-23987.html https://bugzilla.suse.com/1183942 . Several critical updates for MozillaFirefox have just been released in SUSE Security Patch SUSE-SU-2021:1007-1.. SUSE Linux, Mozilla Firefox, security update, important patch, memory safety. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.