Описание
Security update for MozillaThunderbird
This update for MozillaThunderbird fixes the following issues:
Mozilla Thunderbird was updated to version 115.0.1 (bsc#1212438):
- CVE-2023-3600: Fixed use-after-free in workers (bmo#1839703).
- CVE-2023-3417: Fixed File Extension Spoofing using the Text Direction Override Character (bmo#1835582).
Bugfixes:
- changed: Added Thunderbird Supernova branding to about:dialog (bmo#1842102)
- fixed: Message list was not updated when message was deleted from server outside of Thunderbird (bmo#1837041)
- fixed: Scrolling behaved unexpectedly when moving to next message unread message in another folder (bmo#1841711)
- fixed: Scrolling animation was unnecessarily used when switching or toggling the sort column in message list (bmo#1838522)
- fixed: Attempting to delete a message and then cancelling the action still marked the message as read (bmo#793353)
- fixed: Unified Toolbar could not be customized under certain tabs (bmo#1841480)
- fixed: Selecting a folder with one or more subfolders and pressing enter did not expand folder (bmo#1841200)
- fixed: Tooltips did not appear when hovering over folders (bmo#1839780)
- fixed: Deleting large amounts of messages from Trash folder consumed excessive time and memory (bmo#1833665)
- fixed: Message Summary header buttons were not keyboard accessible (bmo#1827199)
- fixed: 'New' button in Message Filters dialog was not keyboard accessible (bmo#1841477)
- fixed: Backing up secret keys from OpenPGP Key Manager dialog silently failed (bmo#1839415)
- fixed: Various visual and UX improvements (bmo#1843172,bmo#1831422,bmo#1838360,bmo#1842319)
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP4
SUSE Linux Enterprise Module for Package Hub 15 SP5
SUSE Linux Enterprise Workstation Extension 15 SP4
SUSE Linux Enterprise Workstation Extension 15 SP5
openSUSE Leap 15.4
openSUSE Leap 15.5
Ссылки
- Link for SUSE-SU-2023:3059-1
- E-Mail link for SUSE-SU-2023:3059-1
- SUSE Security Ratings
- SUSE Bug 1212438
- SUSE CVE CVE-2023-3417 page
- SUSE CVE CVE-2023-3600 page
Описание
Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.
Затронутые продукты
Ссылки
- CVE-2023-3417
- SUSE Bug 1213658
Описание
During the worker lifecycle, a use-after-free condition could have occured, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1.
Затронутые продукты
Ссылки
- CVE-2023-3600
- SUSE Bug 1213230