Bug 31734 - Thunderbird 102.9.1
Summary: Thunderbird 102.9.1
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-03-30 20:15 CEST by David Walser
Modified: 2023-04-11 21:03 CEST (History)
5 users (show)

See Also:
Source RPM: thunderbird, thunderbird-l10n
CVE:
Status comment:


Attachments

Description David Walser 2023-03-30 20:15:23 CEST
Mozilla has released Thunderbird 102.8.0 on March 28:
https://www.thunderbird.net/en-US/thunderbird/102.9.1/releasenotes/

Security issues fixed:
https://www.mozilla.org/en-US/security/advisories/mfsa2023-12/
David Walser 2023-03-30 20:15:40 CEST

Whiteboard: (none) => MGA8TOO

Comment 1 Nicolas Salguero 2023-03-31 14:27:29 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack. (CVE-2023-28427)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28427
https://www.thunderbird.net/en-US/thunderbird/102.9.1/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2023-12/
========================

Updated packages in core/updates_testing:
========================
thunderbird-102.9.1-1.mga8
thunderbird-ka-102.9.1-1.mga8
thunderbird-ru-102.9.1-1.mga8
thunderbird-uk-102.9.1-1.mga8
thunderbird-el-102.9.1-1.mga8
thunderbird-ja-102.9.1-1.mga8
thunderbird-zh_TW-102.9.1-1.mga8
thunderbird-kk-102.9.1-1.mga8
thunderbird-th-102.9.1-1.mga8
thunderbird-sk-102.9.1-1.mga8
thunderbird-vi-102.9.1-1.mga8
thunderbird-hu-102.9.1-1.mga8
thunderbird-zh_CN-102.9.1-1.mga8
thunderbird-cs-102.9.1-1.mga8
thunderbird-hsb-102.9.1-1.mga8
thunderbird-dsb-102.9.1-1.mga8
thunderbird-hy_AM-102.9.1-1.mga8
thunderbird-sr-102.9.1-1.mga8
thunderbird-es_MX-102.9.1-1.mga8
thunderbird-fr-102.9.1-1.mga8
thunderbird-de-102.9.1-1.mga8
thunderbird-tr-102.9.1-1.mga8
thunderbird-es_AR-102.9.1-1.mga8
thunderbird-pl-102.9.1-1.mga8
thunderbird-ko-102.9.1-1.mga8
thunderbird-kab-102.9.1-1.mga8
thunderbird-fy_NL-102.9.1-1.mga8
thunderbird-sq-102.9.1-1.mga8
thunderbird-pt_BR-102.9.1-1.mga8
thunderbird-cy-102.9.1-1.mga8
thunderbird-bg-102.9.1-1.mga8
thunderbird-sv_SE-102.9.1-1.mga8
thunderbird-be-102.9.1-1.mga8
thunderbird-sl-102.9.1-1.mga8
thunderbird-is-102.9.1-1.mga8
thunderbird-nl-102.9.1-1.mga8
thunderbird-lt-102.9.1-1.mga8
thunderbird-eu-102.9.1-1.mga8
thunderbird-et-102.9.1-1.mga8
thunderbird-da-102.9.1-1.mga8
thunderbird-fi-102.9.1-1.mga8
thunderbird-gl-102.9.1-1.mga8
thunderbird-pt_PT-102.9.1-1.mga8
thunderbird-he-102.9.1-1.mga8
thunderbird-hr-102.9.1-1.mga8
thunderbird-ro-102.9.1-1.mga8
thunderbird-ar-102.9.1-1.mga8
thunderbird-nn_NO-102.9.1-1.mga8
thunderbird-es_ES-102.9.1-1.mga8
thunderbird-en_GB-102.9.1-1.mga8
thunderbird-nb_NO-102.9.1-1.mga8
thunderbird-en_CA-102.9.1-1.mga8
thunderbird-pa_IN-102.9.1-1.mga8
thunderbird-en_US-102.9.1-1.mga8
thunderbird-ca-102.9.1-1.mga8
thunderbird-id-102.9.1-1.mga8
thunderbird-gd-102.9.1-1.mga8
thunderbird-it-102.9.1-1.mga8
thunderbird-lv-102.9.1-1.mga8
thunderbird-br-102.9.1-1.mga8
thunderbird-ga_IE-102.9.1-1.mga8
thunderbird-af-102.9.1-1.mga8
thunderbird-ms-102.9.1-1.mga8
thunderbird-ast-102.9.1-1.mga8
thunderbird-uz-102.9.1-1.mga8

from SRPMS:
thunderbird-102.9.1-1.mga8.src.rpm
thunderbird-l10n-102.9.1-1.mga8.src.rpm

Whiteboard: MGA8TOO => (none)
Source RPM: thunderbird => thunderbird, thunderbird-l10n
Status: NEW => ASSIGNED
Assignee: nicolas.salguero => qa-bugs
Version: Cauldron => 8
CC: (none) => nicolas.salguero

Comment 2 Morgan Leijström 2023-04-02 12:28:30 CEST
OK mga8-64, plasma, nvidia-current 4k display, Swedish locale
Clean update
Kept configured accounts, a lot of locally stored emails.
Offline IMAP synk and retrieve, SMTP sending.
Attachements, printing.

CC: (none) => fri

Comment 3 Thomas Andrews 2023-04-08 15:11:38 CEST
No installation issues.

Send and replied email between my Gmail and Yahoo accounts, read newsgroup messages and posted a reply. No issues noted. I do not use the calendar.

Also, I have been using this version with Cauldron on production installs for several days without issues.

Giving this an OK, and validating. Advisory in comment 1.

CC: (none) => andrewsfarm, sysadmin-bugs
Whiteboard: (none) => MGA8-64-OK
Keywords: (none) => validated_update

Dave Hodgins 2023-04-11 00:39:04 CEST

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 4 Mageia Robot 2023-04-11 21:03:44 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0132.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.