Bug 33763 - Thunderbird 128.4.3
Summary: Thunderbird 128.4.3
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-11-14 09:09 CET by Nicolas Salguero
Modified: 2024-11-20 18:24 CET (History)
8 users (show)

See Also:
Source RPM: thunderbird, thunderbird-l10n
CVE: CVE-2024-11159
Status comment:


Attachments

Description Nicolas Salguero 2024-11-14 09:09:01 CET
Mozilla has released Thunderbird 128.4.2 on November 6:
https://www.thunderbird.net/en-US/thunderbird/128.4.2esr/releasenotes/
Mozilla has released Thunderbird 128.4.3 on November 12:
https://www.thunderbird.net/en-US/thunderbird/128.4.3esr/releasenotes/

Security issues fixed:
https://www.mozilla.org/en-US/security/advisories/mfsa2024-61/
Nicolas Salguero 2024-11-14 09:09:32 CET

Source RPM: (none) => thunderbird, thunderbird-l10n
CVE: (none) => CVE-2024-11159
Whiteboard: (none) => MGA9TOO

Comment 1 Nicolas Salguero 2024-11-14 19:44:31 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Potential disclosure of plaintext in OpenPGP encrypted message. (CVE-2024-11159)

References:
https://www.thunderbird.net/en-US/thunderbird/128.4.2esr/releasenotes/
https://www.thunderbird.net/en-US/thunderbird/128.4.3esr/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2024-61/
========================

Updated packages in core/updates_testing:
========================
thunderbird-128.4.3-1.mga9
thunderbird-af-128.4.3-1.mga9
thunderbird-ar-128.4.3-1.mga9
thunderbird-ast-128.4.3-1.mga9
thunderbird-be-128.4.3-1.mga9
thunderbird-bg-128.4.3-1.mga9
thunderbird-br-128.4.3-1.mga9
thunderbird-ca-128.4.3-1.mga9
thunderbird-cs-128.4.3-1.mga9
thunderbird-cy-128.4.3-1.mga9
thunderbird-da-128.4.3-1.mga9
thunderbird-de-128.4.3-1.mga9
thunderbird-dsb-128.4.3-1.mga9
thunderbird-el-128.4.3-1.mga9
thunderbird-en_CA-128.4.3-1.mga9
thunderbird-en_GB-128.4.3-1.mga9
thunderbird-en_US-128.4.3-1.mga9
thunderbird-es_AR-128.4.3-1.mga9
thunderbird-es_ES-128.4.3-1.mga9
thunderbird-es_MX-128.4.3-1.mga9
thunderbird-et-128.4.3-1.mga9
thunderbird-eu-128.4.3-1.mga9
thunderbird-fi-128.4.3-1.mga9
thunderbird-fr-128.4.3-1.mga9
thunderbird-fy_NL-128.4.3-1.mga9
thunderbird-ga_IE-128.4.3-1.mga9
thunderbird-gd-128.4.3-1.mga9
thunderbird-gl-128.4.3-1.mga9
thunderbird-he-128.4.3-1.mga9
thunderbird-hr-128.4.3-1.mga9
thunderbird-hsb-128.4.3-1.mga9
thunderbird-hu-128.4.3-1.mga9
thunderbird-hy_AM-128.4.3-1.mga9
thunderbird-id-128.4.3-1.mga9
thunderbird-is-128.4.3-1.mga9
thunderbird-it-128.4.3-1.mga9
thunderbird-ja-128.4.3-1.mga9
thunderbird-ka-128.4.3-1.mga9
thunderbird-kab-128.4.3-1.mga9
thunderbird-kk-128.4.3-1.mga9
thunderbird-ko-128.4.3-1.mga9
thunderbird-lt-128.4.3-1.mga9
thunderbird-lv-128.4.3-1.mga9
thunderbird-ms-128.4.3-1.mga9
thunderbird-nb_NO-128.4.3-1.mga9
thunderbird-nl-128.4.3-1.mga9
thunderbird-nn_NO-128.4.3-1.mga9
thunderbird-pa_IN-128.4.3-1.mga9
thunderbird-pl-128.4.3-1.mga9
thunderbird-pt_BR-128.4.3-1.mga9
thunderbird-pt_PT-128.4.3-1.mga9
thunderbird-ro-128.4.3-1.mga9
thunderbird-ru-128.4.3-1.mga9
thunderbird-sk-128.4.3-1.mga9
thunderbird-sl-128.4.3-1.mga9
thunderbird-sq-128.4.3-1.mga9
thunderbird-sr-128.4.3-1.mga9
thunderbird-sv_SE-128.4.3-1.mga9
thunderbird-th-128.4.3-1.mga9
thunderbird-tr-128.4.3-1.mga9
thunderbird-uk-128.4.3-1.mga9
thunderbird-uz-128.4.3-1.mga9
thunderbird-vi-128.4.3-1.mga9
thunderbird-zh_CN-128.4.3-1.mga9
thunderbird-zh_TW-128.4.3-1.mga9

from SRPMS:
thunderbird-128.4.3-1.mga9.src.rpm
thunderbird-l10n-128.4.3-1.mga9.src.rpm

Whiteboard: MGA9TOO => (none)
Assignee: bugsquad => qa-bugs
Version: Cauldron => 9
Status: NEW => ASSIGNED

katnatek 2024-11-14 20:31:55 CET

Keywords: (none) => advisory

Comment 2 Herman Viaene 2024-11-15 11:08:18 CET
MGA9-64 Plasma Wayland
No installation issues, overwriting previous version
Tested by sending and receiving e-mails with and without attachment, all work OK

CC: (none) => herman.viaene

Comment 3 Brian Rockwell 2024-11-15 19:27:06 CET
MGA9-64, Gnome

New install

The following 4 packages are going to be installed:

- lib64otr5-4.1.1-5.mga9.x86_64
- thunderbird-128.4.3-1.mga9.x86_64
- thunderbird-compose-1.1-1.mga9.noarch
- thunderbird-en_CA-128.4.3-1.mga9.noarch

254MB of additional disk space will be used.

--

set up mail account
- received mail
- sent mail
- address book working
- calendar seems to work
- chat client is trying, but I forgot my password as usual

CC: (none) => brtians1

Comment 4 Thomas Andrews 2024-11-16 13:05:52 CET
MGA9-64 Plasma. 

Updated the US English version, sent, received, replied, received reply in POP3 mail. Also, no issues with newsgroups.

I do not use the calendar.

CC: (none) => andrewsfarm

Comment 5 Thomas Andrews 2024-11-16 15:31:47 CET
One setting had been changed for me, just as with the last Thunderbird update. 

Some mailing list emails were showing up as coming from the ML instead of identifying the author. Disabling "Show only display name for people in my address book" under "General" in Settings fixed it.

Is this something I'm going to have to check and fix every time I update Thunderbird from now on? That's going to become very annoying, and not just for me.
Comment 6 Len Lawrence 2024-11-17 01:19:40 CET
mga9, x64
Updated OK with the en_GB language pack.
POP3 account, sending and receiving mail.
Settings option "Show only display name for people in my address book" was still disabled.

CC: (none) => tarazed25

Comment 7 Thomas Andrews 2024-11-17 04:32:52 CET
Checked my Pavilion laptop, and the display name setting there remains disabled.

It is quite possible that I neglected to change the setting on my desktop. If no one else sees it change back, then that is most likely what happened. 

Please don't let the news of this imperfection get out - I have a reputation to protect...
Comment 8 Morgan Leijström 2024-11-17 19:48:36 CET
mga9-64 OK here, not full test
Plasma X11

Closed Thunderbird, data backup, updated, started:
Thunderbird just keep working OK:
Opened tabs restored
Settings and local mail kept
Swedish locale
IMAP (offline, IMAP to synk to server)
SMTP
Sent mail with both inline and attached jpg
Received mail with both inline jpg and attached jpg, attached pdf
Viewed attached pdf in Thunderbird, and printed to network printer.

I do not use calendar nor tasks or filters

CC: (none) => fri

Comment 9 Guillaume Royer 2024-11-17 20:13:33 CET
MGA9 X64 GNOME

Tested with RPM:

thunderbird                    128.4.3      1.mga9        x86_64  
thunderbird-fr                 128.4.3      1.mga9        noarch

send mail ok
calendar and contact synchronization ok

CC: (none) => guillaume.royer

Comment 10 Morgan Leijström 2024-11-19 14:23:36 CET
Also in good use by my wife, setup similar to comment 8.
Comment 11 Thomas Andrews 2024-11-19 22:55:00 CET
Looks good to ne. Validating.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update
Whiteboard: (none) => MGA9-64-OK

Comment 12 Jose Manuel López 2024-11-20 08:25:55 CET
Installed yesterday in Mageia 9 x64, Slimbook 4800H and 5700H without issues.

Send and receive ok.
Accouns POP and IMAP ok.
Signature ok.
Settings and addons ok.
Spanish translation ok.
Calendar and task ok.


Launched from terminal:

[jose@localhost ~]$ thunderbird
ATTENTION: default value of option mesa_glthread overridden by environment.
[Parent 117335, Main Thread] WARNING: /usr/share/applications/kde-mimeapps.list contains a [Added Associations] group, but it is not permitted here.  Only the non-desktop-specific mimeapps.list file may add or remove associations.: 'glib warning', file /home/iurt/rpmbuild/BUILD/thunderbird-128.4.3/thunderbird-128.4.3/toolkit/xre/nsSigHandlers.cpp:187

(thunderbird:117335): GLib-GIO-WARNING **: 08:25:26.473: /usr/share/applications/kde-mimeapps.list contains a [Added Associations] group, but it is not permitted here.  Only the non-desktop-specific mimeapps.list file may add or remove associations.

CC: (none) => Joselp

Comment 13 Mageia Robot 2024-11-20 18:24:14 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0365.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.