Bug 31911 - Thunderbird 102.11
Summary: Thunderbird 102.11
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on: 31902
Blocks:
  Show dependency treegraph
 
Reported: 2023-05-11 09:38 CEST by Nicolas Salguero
Modified: 2023-05-18 17:56 CEST (History)
3 users (show)

See Also:
Source RPM: thunderbird, thunderbird-l10n
CVE:
Status comment:


Attachments

Description Nicolas Salguero 2023-05-11 09:38:59 CEST
Mozilla has released Thunderbird 102.11.0 on May 10:
https://www.thunderbird.net/en-US/thunderbird/102.11.0/releasenotes/

Security issues fixed:
https://www.mozilla.org/en-US/security/advisories/mfsa2023-18/
Nicolas Salguero 2023-05-11 09:39:24 CEST

Source RPM: (none) => thunderbird, thunderbird-l10n
Assignee: bugsquad => nicolas.salguero
Whiteboard: (none) => MGA8TOO
CC: (none) => nicolas.salguero

Nicolas Salguero 2023-05-11 09:40:16 CEST

Depends on: (none) => 31902

Comment 1 Nicolas Salguero 2023-05-11 13:51:22 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Browser prompts could have been obscured by popups. (CVE-2023-32205)

Crash in RLBox Expat driver. (CVE-2023-32206)

Potential permissions request bypass via clickjacking. (CVE-2023-32207)

Content process crash due to invalid wasm code. (CVE-2023-32211)

Potential spoof due to obscured address bar. (CVE-2023-32212)

Potential memory corruption in FileReader::DoReadData(). (CVE-2023-32213)

Memory safety bugs fixed in Thunderbird 102.11. (CVE-2023-32215)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32205
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32206
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32206
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32211
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32212
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32213
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32215
https://www.thunderbird.net/en-US/thunderbird/102.11.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2023-18/
========================

Updated packages in core/updates_testing:
========================
thunderbird-102.11.0-1.mga8
thunderbird-ka-102.11.0-1.mga8
thunderbird-ru-102.11.0-1.mga8
thunderbird-uk-102.11.0-1.mga8
thunderbird-el-102.11.0-1.mga8
thunderbird-ja-102.11.0-1.mga8
thunderbird-zh_TW-102.11.0-1.mga8
thunderbird-kk-102.11.0-1.mga8
thunderbird-th-102.11.0-1.mga8
thunderbird-sk-102.11.0-1.mga8
thunderbird-vi-102.11.0-1.mga8
thunderbird-hu-102.11.0-1.mga8
thunderbird-zh_CN-102.11.0-1.mga8
thunderbird-cs-102.11.0-1.mga8
thunderbird-hsb-102.11.0-1.mga8
thunderbird-dsb-102.11.0-1.mga8
thunderbird-hy_AM-102.11.0-1.mga8
thunderbird-sr-102.11.0-1.mga8
thunderbird-es_MX-102.11.0-1.mga8
thunderbird-fr-102.11.0-1.mga8
thunderbird-de-102.11.0-1.mga8
thunderbird-tr-102.11.0-1.mga8
thunderbird-es_AR-102.11.0-1.mga8
thunderbird-pl-102.11.0-1.mga8
thunderbird-ko-102.11.0-1.mga8
thunderbird-kab-102.11.0-1.mga8
thunderbird-fy_NL-102.11.0-1.mga8
thunderbird-sq-102.11.0-1.mga8
thunderbird-pt_BR-102.11.0-1.mga8
thunderbird-cy-102.11.0-1.mga8
thunderbird-bg-102.11.0-1.mga8
thunderbird-sv_SE-102.11.0-1.mga8
thunderbird-be-102.11.0-1.mga8
thunderbird-sl-102.11.0-1.mga8
thunderbird-is-102.11.0-1.mga8
thunderbird-nl-102.11.0-1.mga8
thunderbird-lt-102.11.0-1.mga8
thunderbird-eu-102.11.0-1.mga8
thunderbird-et-102.11.0-1.mga8
thunderbird-da-102.11.0-1.mga8
thunderbird-fi-102.11.0-1.mga8
thunderbird-gl-102.11.0-1.mga8
thunderbird-pt_PT-102.11.0-1.mga8
thunderbird-he-102.11.0-1.mga8
thunderbird-hr-102.11.0-1.mga8
thunderbird-ro-102.11.0-1.mga8
thunderbird-ar-102.11.0-1.mga8
thunderbird-nn_NO-102.11.0-1.mga8
thunderbird-es_ES-102.11.0-1.mga8
thunderbird-en_GB-102.11.0-1.mga8
thunderbird-nb_NO-102.11.0-1.mga8
thunderbird-en_CA-102.11.0-1.mga8
thunderbird-pa_IN-102.11.0-1.mga8
thunderbird-en_US-102.11.0-1.mga8
thunderbird-ca-102.11.0-1.mga8
thunderbird-id-102.11.0-1.mga8
thunderbird-gd-102.11.0-1.mga8
thunderbird-it-102.11.0-1.mga8
thunderbird-lv-102.11.0-1.mga8
thunderbird-br-102.11.0-1.mga8
thunderbird-ga_IE-102.11.0-1.mga8
thunderbird-af-102.11.0-1.mga8
thunderbird-ms-102.11.0-1.mga8
thunderbird-ast-102.11.0-1.mga8
thunderbird-uz-102.11.0-1.mga8

from SRPMS:
thunderbird-102.11.0-1.mga8.src.rpm
thunderbird-l10n-102.11.0-1.mga8.src.rpm

Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8
Status: NEW => ASSIGNED
Assignee: nicolas.salguero => qa-bugs

Comment 2 Dave Hodgins 2023-05-15 21:15:03 CEST
No regressions noticed. Advisory committed to svn. Validating the update.

Keywords: (none) => advisory, validated_update
Whiteboard: (none) => MGA8-64-OK
CC: (none) => davidwhodgins, sysadmin-bugs

Comment 3 Mageia Robot 2023-05-16 21:19:23 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0172.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED

Comment 4 David Walser 2023-05-18 17:56:42 CEST
RedHat has issued an advisory for this on May 16:
https://access.redhat.com/errata/RHSA-2023:3151

Note You need to log in before you can comment on or make changes to this bug.