Bug 30681 - Thunderbird 91.12
Summary: Thunderbird 91.12
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on: 30669
Blocks:
  Show dependency treegraph
 
Reported: 2022-07-29 17:34 CEST by David Walser
Modified: 2022-08-25 23:22 CEST (History)
8 users (show)

See Also:
Source RPM: thunderbird, thunderbird-l10n
CVE:
Status comment:


Attachments

Description David Walser 2022-07-29 17:34:16 CEST
Mozilla has released Thunderbird 91.12.0 on July 26:
https://www.thunderbird.net/en-US/thunderbird/91.12.0/releasenotes/

Security issues fixed:
https://www.mozilla.org/en-US/security/advisories/mfsa2022-31/
David Walser 2022-07-29 17:34:33 CEST

Depends on: (none) => 30669

Comment 1 David Walser 2022-08-01 17:07:38 CEST
RedHat has issued an advisory for this today (August 1):
https://access.redhat.com/errata/RHSA-2022:5778
Comment 2 Nicolas Salguero 2022-08-16 19:27:21 CEST
Suggested advisory:
========================

The updated packages fix security vulnerabilities:

Mouse Position spoofing with CSS transforms. (CVE-2022-36319)

Directory indexes for bundled resources reflected URL parameters. (CVE-2022-36318)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36319
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36318
https://www.thunderbird.net/en-US/thunderbird/91.12.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-31/
https://access.redhat.com/errata/RHSA-2022:5778
========================

Updated packages in core/updates_testing:
========================
thunderbird-91.12.0-1.mga8
thunderbird-ru-91.12.0-1.mga8
thunderbird-uk-91.12.0-1.mga8
thunderbird-ka-91.12.0-1.mga8
thunderbird-el-91.12.0-1.mga8
thunderbird-th-91.12.0-1.mga8
thunderbird-ja-91.12.0-1.mga8
thunderbird-kk-91.12.0-1.mga8
thunderbird-zh_TW-91.12.0-1.mga8
thunderbird-zh_CN-91.12.0-1.mga8
thunderbird-hy_AM-91.12.0-1.mga8
thunderbird-sk-91.12.0-1.mga8
thunderbird-hu-91.12.0-1.mga8
thunderbird-dsb-91.12.0-1.mga8
thunderbird-vi-91.12.0-1.mga8
thunderbird-hsb-91.12.0-1.mga8
thunderbird-sr-91.12.0-1.mga8
thunderbird-cs-91.12.0-1.mga8
thunderbird-fr-91.12.0-1.mga8
thunderbird-ko-91.12.0-1.mga8
thunderbird-sq-91.12.0-1.mga8
thunderbird-lt-91.12.0-1.mga8
thunderbird-be-91.12.0-1.mga8
thunderbird-bg-91.12.0-1.mga8
thunderbird-es_AR-91.12.0-1.mga8
thunderbird-de-91.12.0-1.mga8
thunderbird-tr-91.12.0-1.mga8
thunderbird-pl-91.12.0-1.mga8
thunderbird-pt_BR-91.12.0-1.mga8
thunderbird-fy_NL-91.12.0-1.mga8
thunderbird-sv_SE-91.12.0-1.mga8
thunderbird-kab-91.12.0-1.mga8
thunderbird-nl-91.12.0-1.mga8
thunderbird-cy-91.12.0-1.mga8
thunderbird-gl-91.12.0-1.mga8
thunderbird-eu-91.12.0-1.mga8
thunderbird-he-91.12.0-1.mga8
thunderbird-pt_PT-91.12.0-1.mga8
thunderbird-fi-91.12.0-1.mga8
thunderbird-ar-91.12.0-1.mga8
thunderbird-sl-91.12.0-1.mga8
thunderbird-ro-91.12.0-1.mga8
thunderbird-da-91.12.0-1.mga8
thunderbird-nn_NO-91.12.0-1.mga8
thunderbird-nb_NO-91.12.0-1.mga8
thunderbird-pa_IN-91.12.0-1.mga8
thunderbird-hr-91.12.0-1.mga8
thunderbird-ca-91.12.0-1.mga8
thunderbird-id-91.12.0-1.mga8
thunderbird-en_GB-91.12.0-1.mga8
thunderbird-gd-91.12.0-1.mga8
thunderbird-en_CA-91.12.0-1.mga8
thunderbird-en_US-91.12.0-1.mga8
thunderbird-br-91.12.0-1.mga8
thunderbird-lv-91.12.0-1.mga8
thunderbird-it-91.12.0-1.mga8
thunderbird-ga_IE-91.12.0-1.mga8
thunderbird-et-91.12.0-1.mga8
thunderbird-uz-91.12.0-1.mga8
thunderbird-ast-91.12.0-1.mga8
thunderbird-is-91.12.0-1.mga8
thunderbird-ms-91.12.0-1.mga8
thunderbird-es_ES-91.12.0-1.mga8
thunderbird-af-91.12.0-1.mga8

from SRPMS:
thunderbird-91.12.0-1.mga8.src.rpm
thunderbird-l10n-91.12.0-1.mga8.src.rpm

Status: NEW => ASSIGNED
Assignee: nicolas.salguero => qa-bugs
Source RPM: thunderbird => thunderbird, thunderbird-l10n

Nicolas Salguero 2022-08-16 19:27:34 CEST

CC: (none) => nicolas.salguero

Comment 3 Herman Viaene 2022-08-19 11:07:37 CEST
MGA8-64 Plasma on Acer Aspire 5253
No installation  issues.
This is an upgrade on an existing 91.11 with a hotmail account configured.
Sending and receiving mail without and with attachment gets across OK, with one remark: every mail I send gets listed twice in the "Sent" box, but it is only once seen (as expected) at the receiving end.
I wonder whether others seem the same behavior.

CC: (none) => herman.viaene

Comment 4 Jose Manuel López 2022-08-19 17:59:05 CEST
Mga8 x64 on Slimbook ProX 14 AMD

Updated from 91.11 version. No issues, addons ok, calendar, task, sent and receive emails, signature ok. I'm working right now for this version without problems. Language ES-es ok.

CC: (none) => joselp

Comment 5 Guillaume Royer 2022-08-21 15:45:52 CEST
MGA8-64 updated with QArepo:

thunderbird                    91.12.0      1.mga8        x86_64  
thunderbird-fr                 91.12.0      1.mga8        noarch  

No issues after installation. 

Send and receive mail with SMTP protocol Ok
Calendar Synchro Ok

CC: (none) => guillaume.royer

Comment 6 Morgan Leijström 2022-08-22 13:49:39 CEST
mga8-64 OK for me on Plasma, nvidia-current, 4K screenn Swedish locale
Updated using drakrpm

Settings and local mail preserved
SMTP, IMAP offline and online
Not using calendar, filters etc.

CC: (none) => fri

Comment 7 Thomas Andrews 2022-08-22 15:42:30 CEST
No installation issues for US, CA, GB English versions. Sent and received POP mail, looked at newsgroups, all went well.

@Herman: I don't have a Hotmail account, but I sent mail to gmail from yahoo and back, ant the sent folder only listed each once. 

OKing, based on all these tests, and validating. Advisory in Comment 2.

Whiteboard: (none) => MGA8-64-OK
Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2022-08-24 23:00:39 CEST

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 8 Mageia Robot 2022-08-25 23:22:59 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0300.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.