Bug 26891 - Thunderbird 68.10
Summary: Thunderbird 68.10
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on: 26890
Blocks: 26705
  Show dependency treegraph
 
Reported: 2020-07-02 21:43 CEST by David Walser
Modified: 2020-08-01 01:27 CEST (History)
7 users (show)

See Also:
Source RPM: thunderbird
CVE:
Status comment:


Attachments

Description David Walser 2020-07-02 21:43:52 CEST
Mozilla has released Thunderbird 68.10.0 on July 1:
https://www.thunderbird.net/en-US/thunderbird/68.10.0/releasenotes/

It fixes security issues:
https://www.mozilla.org/en-US/security/advisories/mfsa2020-26/

We should wait to build it until Thunderbird 68.9.0 has been pushed (Bug 26705).
David Walser 2020-07-02 21:44:11 CEST

Depends on: (none) => 26890

Comment 1 David Walser 2020-07-02 21:44:56 CEST
You might want to double check that thunderbird-l10n is correct, as I found several languages that should have been added in firefox-l10n when it was bumped to 68.0, which I just fixed in 68.10.
Comment 2 David Walser 2020-07-02 23:28:54 CEST
Actually you might as well build it, Firefox 68.9 never got pushed either.
David Walser 2020-07-02 23:33:43 CEST

Blocks: (none) => 26705

David Walser 2020-07-07 21:31:48 CEST

CC: (none) => nicolas.salguero

Thomas Andrews 2020-07-07 22:50:58 CEST

CC: (none) => andrewsfarm

Comment 3 David Walser 2020-07-10 20:21:21 CEST
Fedora has issued an advisory for this today (July 10):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/OUYAQVBJJNHI2M2LJ57FZB5BJCANBXWT/
Comment 4 Nicolas Salguero 2020-07-11 10:30:04 CEST
There is also a new version of enigmail.
Comment 5 José Jorge 2020-07-11 15:28:01 CEST
Working on it...
Comment 6 David Walser 2020-07-11 19:40:39 CEST
Here's a start on the advisory.  Add anything you need to add to it (about updated enigmail or whatever).

Advisory:
========================

Updated thunderbird packages fix security vulnerabilities:

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server
sends a PREAUTH response, then Thunderbird will continue with an unencrypted
connection, causing email data to be sent without protection (CVE-2020-12398).

When browsing a malicious page, a race condition in our SharedWorkerService
could occur and lead to a potentially exploitable crash due to a use-after-free
(CVE-2020-12405).

Mozilla developer Iain Ireland discovered a missing type check during unboxed
objects removal, resulting in a crash due to type confusion with NativeTypes. We
presume that with enough effort that it could be exploited to run arbitrary code
(CVE-2020-12406).

Mozilla developers Tom Tung and Karl Tomlinson reported memory safety bugs
present in Firefox ESR 68.8. Some of these bugs showed evidence of memory
corruption and we presume that with enough effort some of these could have been
exploited to run arbitrary code (CVE-2020-12410).

Manipulating individual parts of a URL object could have caused an
out-of-bounds read, leaking process memory to malicious JavaScript
(CVE-2020-12418).

When processing callbacks that occurred during window flushing in the parent
process, the associated window may die; causing a use-after-free in
nsGlobalWindowInner. This could have led to memory corruption and a
potentially exploitable crash (CVE-2020-12419).

When trying to connect to a STUN server, a race condition could have caused a
use-after-free of a pointer, leading to memory corruption and a potentially
exploitable crash (CVE-2020-12420).

If an attacker intercepts Thunderbird's initial attempt to perform automatic
account setup using the Microsoft Exchange autodiscovery mechanism, and the
attacker sends a crafted response, then Thunderbird sends username and
password over https to a server controlled by the attacker (MFSA-2020-0001).

When performing add-on updates, certificate chains terminating in
non-built-in-roots were rejected (even if they were legitimately added by an
administrator.) This could have caused add-ons to become out-of-date silently
without notification to the user (CVE-2020-12421).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12398
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12405
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12406
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12410
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12418
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12419
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12420
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12421
https://www.mozilla.org/en-US/security/advisories/mfsa2020-22/
https://www.mozilla.org/en-US/security/advisories/mfsa2020-26/
========================

Updated packages in core/updates_testing:
========================
thunderbird-68.10.0-1.mga7
thunderbird-enigmail-68.10.0-1.mga7
thunderbird-ar-68.10.0-1.mga7
thunderbird-ast-68.10.0-1.mga7
thunderbird-be-68.10.0-1.mga7
thunderbird-bg-68.10.0-1.mga7
thunderbird-br-68.10.0-1.mga7
thunderbird-ca-68.10.0-1.mga7
thunderbird-cak-68.10.0-1.mga7
thunderbird-cs-68.10.0-1.mga7
thunderbird-cy-68.10.0-1.mga7
thunderbird-da-68.10.0-1.mga7
thunderbird-de-68.10.0-1.mga7
thunderbird-el-68.10.0-1.mga7
thunderbird-en_GB-68.10.0-1.mga7
thunderbird-en_US-68.10.0-1.mga7
thunderbird-es_AR-68.10.0-1.mga7
thunderbird-es_ES-68.10.0-1.mga7
thunderbird-et-68.10.0-1.mga7
thunderbird-eu-68.10.0-1.mga7
thunderbird-fi-68.10.0-1.mga7
thunderbird-fr-68.10.0-1.mga7
thunderbird-fy_NL-68.10.0-1.mga7
thunderbird-ga_IE-68.10.0-1.mga7
thunderbird-gd-68.10.0-1.mga7
thunderbird-gl-68.10.0-1.mga7
thunderbird-he-68.10.0-1.mga7
thunderbird-hr-68.10.0-1.mga7
thunderbird-hsb-68.10.0-1.mga7
thunderbird-hu-68.10.0-1.mga7
thunderbird-hy_AM-68.10.0-1.mga7
thunderbird-id-68.10.0-1.mga7
thunderbird-is-68.10.0-1.mga7
thunderbird-it-68.10.0-1.mga7
thunderbird-ja-68.10.0-1.mga7
thunderbird-ka-68.10.0-1.mga7
thunderbird-kab-68.10.0-1.mga7
thunderbird-kk-68.10.0-1.mga7
thunderbird-ko-68.10.0-1.mga7
thunderbird-lt-68.10.0-1.mga7
thunderbird-ms-68.10.0-1.mga7
thunderbird-nb_NO-68.10.0-1.mga7
thunderbird-nl-68.10.0-1.mga7
thunderbird-nn_NO-68.10.0-1.mga7
thunderbird-pl-68.10.0-1.mga7
thunderbird-pt_BR-68.10.0-1.mga7
thunderbird-pt_PT-68.10.0-1.mga7
thunderbird-ro-68.10.0-1.mga7
thunderbird-ru-68.10.0-1.mga7
thunderbird-si-68.10.0-1.mga7
thunderbird-sk-68.10.0-1.mga7
thunderbird-sl-68.10.0-1.mga7
thunderbird-sq-68.10.0-1.mga7
thunderbird-sv_SE-68.10.0-1.mga7
thunderbird-tr-68.10.0-1.mga7
thunderbird-uk-68.10.0-1.mga7
thunderbird-uz-68.10.0-1.mga7
thunderbird-vi-68.10.0-1.mga7
thunderbird-zh_CN-68.10.0-1.mga7
thunderbird-zh_TW-68.10.0-1.mga7

from SRPMS:
thunderbird-68.10.0-1.mga7.src.rpm
thunderbird-l10n-68.10.0-1.mga7.src.rpm
José Jorge 2020-07-12 01:18:51 CEST

Assignee: lists.jjorge => qa-bugs

Comment 7 Thomas Andrews 2020-07-12 12:46:32 CEST
64-bit Plasma system, Intel graphics.

Updated the US English version, no installation issues. Was able to send and receive POP mail and use newsgroups. I do not use the calendar or enigmail, but it's working OK for what I do with it.
Comment 8 Morgan Leijström 2020-07-13 00:29:33 CEST
64-bit Plasma, Nvidia proprietary
OK: Swedish, SMTP, offline IMAP

CC: (none) => fri

Comment 9 James Kerr 2020-07-13 06:59:04 CEST
On mga7-64  kernel-desktop  plasma

packages installed cleanly:
- thunderbird-68.10.0-1.mga7.x86_64
- thunderbird-en_GB-68.10.0-1.mga7.noarch

email (POP, SMTP):  OK
Calendar: OK
Address book: OK
Movemail: OK

I don't use enigmail or IMAP

looks OK for mga7-64

CC: (none) => jim

Comment 10 David Walser 2020-07-14 16:11:27 CEST
RedHat has issued an advisory for this today (July 14):
https://access.redhat.com/errata/RHSA-2020:2906
Comment 11 Len Lawrence 2020-07-14 16:17:42 CEST
mga7, x64

thunderbird-en_GB working fine here for IMAP.  Tested calendar reminder function - worked OK.
Moved a group of emails to a local folder.  No regressions.

CC: (none) => tarazed25

Comment 12 Thomas Andrews 2020-07-15 22:43:33 CEST
Good enough. Giving it an OK and validating. Advisory in Comment 6, though from reading the comment I'm not sure that one is complete enough.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update
Whiteboard: (none) => MGA7-64-OK

Comment 13 David Walser 2020-07-15 23:02:21 CEST
Yeah I was hoping he'd add a blurb and reference for the enigmail update.
Dave Hodgins 2020-07-31 08:34:28 CEST

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 14 Mageia Robot 2020-08-01 01:27:51 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0300.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.