Bug 30129 - Thunderbird 91.6.2
Summary: Thunderbird 91.6.2
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on: 30124
Blocks:
  Show dependency treegraph
 
Reported: 2022-03-07 15:35 CET by Nicolas Salguero
Modified: 2022-03-14 17:22 CET (History)
4 users (show)

See Also:
Source RPM: thunderbird, thunderbird-l10n
CVE:
Status comment:


Attachments

Description Nicolas Salguero 2022-03-07 15:35:03 CET
Mozilla has released Thunderbird 91.6.2 on March 5:
https://www.thunderbird.net/en-US/thunderbird/91.6.2/releasenotes/

It fixes bugs and a security issue:
https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/
Nicolas Salguero 2022-03-07 15:35:29 CET

Whiteboard: (none) => MGA8TOO
Source RPM: (none) => thunderbird, thunderbird-l10n
Assignee: bugsquad => nicolas.salguero
CC: (none) => nicolas.salguero

Comment 1 David Walser 2022-03-07 17:32:28 CET
Advisory:
========================

Updated thunderbird packages fix security vulnerabilities:

Removing an XSLT parameter during processing could have lead to an exploitable
use-after-free (CVE-2022-26485).

An unexpected message in the WebGPU IPC framework could lead to a
use-after-free and exploitable sandbox escape (CVE-2022-26486).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26485
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26486
https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/
https://www.thunderbird.net/en-US/thunderbird/91.6.2/releasenotes/

Depends on: (none) => 30124

Comment 2 Nicolas Salguero 2022-03-08 10:07:13 CET
Updated packages in core/updates_testing:
========================
thunderbird-91.6.2-1.mga8
thunderbird-ru-91.6.2-1.mga8
thunderbird-uk-91.6.2-1.mga8
thunderbird-ka-91.6.2-1.mga8
thunderbird-el-91.6.2-1.mga8
thunderbird-th-91.6.2-1.mga8
thunderbird-ja-91.6.2-1.mga8
thunderbird-kk-91.6.2-1.mga8
thunderbird-zh_TW-91.6.2-1.mga8
thunderbird-zh_CN-91.6.2-1.mga8
thunderbird-hy_AM-91.6.2-1.mga8
thunderbird-sk-91.6.2-1.mga8
thunderbird-hu-91.6.2-1.mga8
thunderbird-dsb-91.6.2-1.mga8
thunderbird-vi-91.6.2-1.mga8
thunderbird-hsb-91.6.2-1.mga8
thunderbird-sr-91.6.2-1.mga8
thunderbird-cs-91.6.2-1.mga8
thunderbird-fr-91.6.2-1.mga8
thunderbird-ko-91.6.2-1.mga8
thunderbird-sq-91.6.2-1.mga8
thunderbird-lt-91.6.2-1.mga8
thunderbird-be-91.6.2-1.mga8
thunderbird-bg-91.6.2-1.mga8
thunderbird-es_AR-91.6.2-1.mga8
thunderbird-de-91.6.2-1.mga8
thunderbird-tr-91.6.2-1.mga8
thunderbird-pl-91.6.2-1.mga8
thunderbird-pt_BR-91.6.2-1.mga8
thunderbird-fy_NL-91.6.2-1.mga8
thunderbird-sv_SE-91.6.2-1.mga8
thunderbird-kab-91.6.2-1.mga8
thunderbird-nl-91.6.2-1.mga8
thunderbird-cy-91.6.2-1.mga8
thunderbird-gl-91.6.2-1.mga8
thunderbird-eu-91.6.2-1.mga8
thunderbird-he-91.6.2-1.mga8
thunderbird-pt_PT-91.6.2-1.mga8
thunderbird-fi-91.6.2-1.mga8
thunderbird-ar-91.6.2-1.mga8
thunderbird-sl-91.6.2-1.mga8
thunderbird-ro-91.6.2-1.mga8
thunderbird-da-91.6.2-1.mga8
thunderbird-nn_NO-91.6.2-1.mga8
thunderbird-nb_NO-91.6.2-1.mga8
thunderbird-pa_IN-91.6.2-1.mga8
thunderbird-hr-91.6.2-1.mga8
thunderbird-ca-91.6.2-1.mga8
thunderbird-id-91.6.2-1.mga8
thunderbird-en_GB-91.6.2-1.mga8
thunderbird-gd-91.6.2-1.mga8
thunderbird-en_CA-91.6.2-1.mga8
thunderbird-en_US-91.6.2-1.mga8
thunderbird-br-91.6.2-1.mga8
thunderbird-lv-91.6.2-1.mga8
thunderbird-it-91.6.2-1.mga8
thunderbird-ga_IE-91.6.2-1.mga8
thunderbird-et-91.6.2-1.mga8
thunderbird-uz-91.6.2-1.mga8
thunderbird-ast-91.6.2-1.mga8
thunderbird-is-91.6.2-1.mga8
thunderbird-ms-91.6.2-1.mga8
thunderbird-es_ES-91.6.2-1.mga8
thunderbird-af-91.6.2-1.mga8

from SRPMS:
thunderbird-91.6.2-1.mga8.src.rpm
thunderbird-l10n-91.6.2-1.mga8.src.rpm

Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)
Assignee: nicolas.salguero => qa-bugs
Status: NEW => ASSIGNED

Comment 3 Jose Manuel López 2022-03-08 10:55:48 CET
Hi,

I have tested in Mga real installation. Works fine for me with three accounts, send and receive, settings, signatures, addons.

Greetings!

CC: (none) => joselp

Comment 4 David Walser 2022-03-08 18:52:39 CET
Validating.  Advisory committed in SVN.

Whiteboard: (none) => MGA8-64-OK
Keywords: (none) => advisory, validated_update
CC: (none) => sysadmin-bugs

Comment 5 Mageia Robot 2022-03-08 19:57:04 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0094.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED

Comment 6 Morgan Leijström 2022-03-08 23:03:45 CET
Bugs today are too fast for me...

mga8-64 OK Swedish, Plasma, IMAP, SMTP...

CC: (none) => fri

Comment 7 David Walser 2022-03-14 17:22:35 CET
RedHat has issued an advisory for this today (March 14):
https://access.redhat.com/errata/RHSA-2022:0845

Note You need to log in before you can comment on or make changes to this bug.