Описание
Security update for MozillaThunderbird
This update for MozillaThunderbird fixes the following issues:
Security fixes:
- CVE-2023-5217: Fixed a heap buffer overflow in libvpx. (bsc#1215814)
- CVE-2023-5168: Out-of-bounds write in FilterNodeD2D1. (bsc#1215575)
- CVE-2023-5169: Out-of-bounds write in PathOps. (bsc#1215575)
- CVE-2023-5171: Use-after-free in Ion Compiler. (bsc#1215575)
- CVE-2023-5174: Double-free in process spawning on Windows. (bsc#1215575)
- CVE-2023-5176: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. (bsc#1215575)
Other fixes:
- Mozilla Thunderbird 115.3.1
- fixed: In Unified Folders view, some folders had incorrect unified folder parent (bmo#1852525)
- fixed: 'Edit message as new' did not restore encrypted subject from selected message (bmo#1788534)
- fixed: Importing some CalDAV calendars with yearly recurrence events caused Thunderbird to freeze (bmo#1850732)
- fixed: Security fixes MFSA 2023-44 (bsc#1215814)
- CVE-2023-5217 (bmo#1855550) Heap buffer overflow in libvpx
- Mozilla Thunderbird 115.3
- fixed: Thunderbird could not import profiles with hostname ending in dot ('.') (bmo#1825374)
- fixed: Message header was occasionally missing in message preview (bmo#1840943)
- fixed: Setting an existing folder's type flag did not add descendant folders to the Unified Folders view (bmo#1848904)
- fixed: Thunderbird did not always delete all temporary mail files, sometimes preventing messages from being sent (bmo#673703)
- fixed: Status bar in Message Compose window could not be hidden (bmo#1806860)
- fixed: Message header was intermittently missing from message preview (bmo#1840943)
- fixed: OAuth2 did not work on some profiles created in Thunderbird 102.6.1 or earlier (bmo#1814823)
- fixed: In Vertical View, decrypted subject lines were displayed as ellipsis ('...') in message list (bmo#1831764)
- fixed: Condensed address preference (mail.showCondensedAddresses) did not show condensed addresses in message list (bmo#1831280)
- fixed: Spam folder could not be assigned non-ASCII names with IMAP UTF-8 enabled (bmo#1816332)
- fixed: Message header was not displayed until images finished loading, causing noticeable delay for messages containing large images (bmo#1851871)
- fixed: Large SVG favicons did not display on RSS feeds (bmo#1853895)
- fixed: Context menu items did not display a hover background color (bmo#1852732)
- fixed: Security fixes MFSA 2023-43 (bsc#1215575)
- CVE-2023-5168 (bmo#1846683) Out-of-bounds write in FilterNodeD2D1
- CVE-2023-5169 (bmo#1846685) Out-of-bounds write in PathOps
- CVE-2023-5171 (bmo#1851599) Use-after-free in Ion Compiler
- CVE-2023-5174 (bmo#1848454) Double-free in process spawning on Windows
- CVE-2023-5176 (bmo#1836353, bmo#1842674, bmo#1843824, bmo#1843962, bmo#1848890, bmo#1850180, bmo#1850983, bmo#1851195) Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3
- Add patch mozilla-fix-broken-ffmpeg.patch to fix broken build with newer binutils (bsc#1215309)
- Fix i586 build by reducing debug info to -g1. (bsc#1210168)
- Mozilla Thunderbird 115.2.3
- changed: Card view and vertical layout are now default for new profiles (bmo#1849000)
- fixed: Go - Folder menu was disabled (bmo#1849919)
- fixed: 'Tools' menu was blank when opened from compose window on macOS (bmo#1848155)
- fixed: Deleting an attachment from a message on an IMAP server corrupted the local copy when configured with 'mark as deleted' (bmo#1135434)
- fixed: Manually entered passwords were not remembered for OAuth-authenticated accounts such as Yahoo mail (bmo#1673446)
- fixed: Quick Filter's 'Keep filters applied' did not persist after restarting Thunderbird (bmo#1846880,bmo#1849221)
- fixed: Top-level Quick Filter settings did not persist after restart (bmo#1849249)
- fixed: Notifications for new messages with non-ASCII characters in the subject were garbled (bmo#1842384)
- fixed: 'Mark Thread As Read' did not work when some messages in thread were already read (bmo#1850850)
- fixed: New Groups tab in NNTP subscribe dialog id not work as expected (bmo#1848366)
- fixed: Negative values were allowed in 'Share for files larger than' field (bmo#1850281)
- fixed: Thunderbird sometimes crashed when deleting a parent folder with subfolders (bmo#1851293)
- fixed: 'Send Message Error' appeared intermittently while Thunderbird was idle (bmo#1801668)
- fixed: Focused but not selected messages were missing visual indication of focus in card view (bmo#1844263)
- fixed: Notification dot did not disappear from taskbar icon on Windows after messages had already been read (bmo#1824889)
- fixed: Multiple selected messages could not be opened simultaneously if selection included more than 19 messages (bmo#1851563)
- fixed: Email replies received via BCC incorrectly populated From field with default identity (bmo#1851512)
- fixed: User was not always notified of message send failures in outbox (bmo#1851542)
- fixed: Tag dialog did not close properly after editing tag (bmo#1852414)
- fixed: Newsgroup field in compose window did not autocomplete with suggested newsgroup names (bmo#1670457)
- fixed: Canceling newsgroup messages did not check if sender matched user's own identity (bmo#1823274)
- fixed: Event dialog with several invitees expanded beyond screen height (bmo#1848261)
- fixed: Message check boxes were partially obstructed in message list (bmo#1850760)
- unresolved: Some folders missing from Unified Folders ()
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP4
SUSE Linux Enterprise Module for Package Hub 15 SP5
SUSE Linux Enterprise Workstation Extension 15 SP4
SUSE Linux Enterprise Workstation Extension 15 SP5
openSUSE Leap 15.4
openSUSE Leap 15.5
Ссылки
- Link for SUSE-SU-2023:4016-1
- E-Mail link for SUSE-SU-2023:4016-1
- SUSE Security Ratings
- SUSE Bug 1210168
- SUSE Bug 1215309
- SUSE Bug 1215575
- SUSE Bug 1215814
- SUSE CVE CVE-2023-5168 page
- SUSE CVE CVE-2023-5169 page
- SUSE CVE CVE-2023-5171 page
- SUSE CVE CVE-2023-5174 page
- SUSE CVE CVE-2023-5176 page
- SUSE CVE CVE-2023-5217 page
Описание
A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
Затронутые продукты
Ссылки
- CVE-2023-5168
- SUSE Bug 1215575
Описание
A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
Затронутые продукты
Ссылки
- CVE-2023-5169
- SUSE Bug 1215575
Описание
During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
Затронутые продукты
Ссылки
- CVE-2023-5171
- SUSE Bug 1215575
Описание
If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
Затронутые продукты
Ссылки
- CVE-2023-5174
- SUSE Bug 1215575
Описание
Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
Затронутые продукты
Ссылки
- CVE-2023-5176
- SUSE Bug 1215575
Описание
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-5217
- SUSE Bug 1215776
- SUSE Bug 1215778
- SUSE Bug 1215814
- SUSE Bug 1217559