Lucene search

K
centosCentOS ProjectCESA-2023:0817
HistoryFeb 22, 2023 - 5:48 p.m.

thunderbird security update

2023-02-2217:48:54
CentOS Project
lists.centos.org
31
mozilla thunderbird
security update
version 102.8.0
cve-2023-25728
cve-2023-25730
cve-2023-25735
cve-2023-25737
cve-2023-25739
cve-2023-25743
cve-2023-25744
cve-2023-25746
cve-2023-25729
cve-2023-25732
cve-2023-0616
cve-2023-25742

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

60.6%

CentOS Errata and Security Advisory CESA-2023:0817

Mozilla Thunderbird is a standalone mail and newsgroup client.

This update upgrades Thunderbird to version 102.8.0.

Security Fix(es):

  • Mozilla: Content security policy leak in violation reports using iframes (CVE-2023-25728)

  • Mozilla: Screen hijack via browser fullscreen mode (CVE-2023-25730)

  • Mozilla: Potential use-after-free from compartment mismatch in SpiderMonkey (CVE-2023-25735)

  • Mozilla: Invalid downcast in SVGUtils::SetupStrokeGeometry (CVE-2023-25737)

  • Mozilla: Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext (CVE-2023-25739)

  • Mozilla: Fullscreen notification not shown in Firefox Focus (CVE-2023-25743)

  • Mozilla: Memory safety bugs fixed in Firefox 110 and Firefox ESR 102.8 (CVE-2023-25744)

  • Mozilla: Memory safety bugs fixed in Firefox ESR 102.8 (CVE-2023-25746)

  • Mozilla: Extensions could have opened external schemes without user knowledge (CVE-2023-25729)

  • Mozilla: Out of bounds memory write from EncodeInputStream (CVE-2023-25732)

  • Mozilla: User Interface lockup with messages combining S/MIME and OpenPGP (CVE-2023-0616)

  • Mozilla: Web Crypto ImportKey crashes tab (CVE-2023-25742)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2023-February/086375.html

Affected packages:
thunderbird

Upstream details at:
https://access.redhat.com/errata/RHSA-2023:0817

OSVersionArchitecturePackageVersionFilename
CentOS7x86_64thunderbird< 102.8.0-2.el7.centosthunderbird-102.8.0-2.el7.centos.x86_64.rpm

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

60.6%