Bug 33852 - Thunderbird 128.5.2
Summary: Thunderbird 128.5.2
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-12-13 14:59 CET by Nicolas Salguero
Modified: 2024-12-21 21:17 CET (History)
6 users (show)

See Also:
Source RPM: thunderbird, thunderbird-l10n
CVE: CVE-2024-50336
Status comment:


Attachments

Description Nicolas Salguero 2024-12-13 14:59:57 CET
Mozilla has released Thunderbird 128.5.2 on December 11:
https://www.thunderbird.net/en-US/thunderbird/128.5.2esr/releasenotes/

Security issue fixed:
https://www.mozilla.org/en-US/security/advisories/mfsa2024-69/
Nicolas Salguero 2024-12-13 15:00:19 CET

CVE: (none) => CVE-2024-50336
Whiteboard: (none) => MGA9TOO
Source RPM: (none) => thunderbird, thunderbird-l10n

Comment 1 Nicolas Salguero 2024-12-16 13:09:15 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Matrix-js-sdk has insufficient MXC URI validation which could allow client-side path traversal. (CVE-2024-50336)

References:
https://www.thunderbird.net/en-US/thunderbird/128.5.2esr/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2024-69/
========================

Updated packages in core/updates_testing:
========================
thunderbird-128.5.2-1.mga9
thunderbird-af-128.5.2-1.mga9
thunderbird-ar-128.5.2-1.mga9
thunderbird-ast-128.5.2-1.mga9
thunderbird-be-128.5.2-1.mga9
thunderbird-bg-128.5.2-1.mga9
thunderbird-br-128.5.2-1.mga9
thunderbird-ca-128.5.2-1.mga9
thunderbird-cs-128.5.2-1.mga9
thunderbird-cy-128.5.2-1.mga9
thunderbird-da-128.5.2-1.mga9
thunderbird-de-128.5.2-1.mga9
thunderbird-dsb-128.5.2-1.mga9
thunderbird-el-128.5.2-1.mga9
thunderbird-en_CA-128.5.2-1.mga9
thunderbird-en_GB-128.5.2-1.mga9
thunderbird-en_US-128.5.2-1.mga9
thunderbird-es_AR-128.5.2-1.mga9
thunderbird-es_ES-128.5.2-1.mga9
thunderbird-es_MX-128.5.2-1.mga9
thunderbird-et-128.5.2-1.mga9
thunderbird-eu-128.5.2-1.mga9
thunderbird-fi-128.5.2-1.mga9
thunderbird-fr-128.5.2-1.mga9
thunderbird-fy_NL-128.5.2-1.mga9
thunderbird-ga_IE-128.5.2-1.mga9
thunderbird-gd-128.5.2-1.mga9
thunderbird-gl-128.5.2-1.mga9
thunderbird-he-128.5.2-1.mga9
thunderbird-hr-128.5.2-1.mga9
thunderbird-hsb-128.5.2-1.mga9
thunderbird-hu-128.5.2-1.mga9
thunderbird-hy_AM-128.5.2-1.mga9
thunderbird-id-128.5.2-1.mga9
thunderbird-is-128.5.2-1.mga9
thunderbird-it-128.5.2-1.mga9
thunderbird-ja-128.5.2-1.mga9
thunderbird-ka-128.5.2-1.mga9
thunderbird-kab-128.5.2-1.mga9
thunderbird-kk-128.5.2-1.mga9
thunderbird-ko-128.5.2-1.mga9
thunderbird-lt-128.5.2-1.mga9
thunderbird-lv-128.5.2-1.mga9
thunderbird-ms-128.5.2-1.mga9
thunderbird-nb_NO-128.5.2-1.mga9
thunderbird-nl-128.5.2-1.mga9
thunderbird-nn_NO-128.5.2-1.mga9
thunderbird-pa_IN-128.5.2-1.mga9
thunderbird-pl-128.5.2-1.mga9
thunderbird-pt_BR-128.5.2-1.mga9
thunderbird-pt_PT-128.5.2-1.mga9
thunderbird-ro-128.5.2-1.mga9
thunderbird-ru-128.5.2-1.mga9
thunderbird-sk-128.5.2-1.mga9
thunderbird-sl-128.5.2-1.mga9
thunderbird-sq-128.5.2-1.mga9
thunderbird-sr-128.5.2-1.mga9
thunderbird-sv_SE-128.5.2-1.mga9
thunderbird-th-128.5.2-1.mga9
thunderbird-tr-128.5.2-1.mga9
thunderbird-uk-128.5.2-1.mga9
thunderbird-uz-128.5.2-1.mga9
thunderbird-vi-128.5.2-1.mga9
thunderbird-zh_CN-128.5.2-1.mga9
thunderbird-zh_TW-128.5.2-1.mga9

from SRPMS:
thunderbird-128.5.2-1.mga9.src.rpm
thunderbird-l10n-128.5.2-1.mga9.src.rpm

Status: NEW => ASSIGNED
Whiteboard: MGA9TOO => (none)
Version: Cauldron => 9
Assignee: bugsquad => qa-bugs

katnatek 2024-12-16 19:17:20 CET

Keywords: (none) => advisory

Comment 2 Thomas Andrews 2024-12-16 21:38:13 CET
MGA9-64 Plasma on two different systems.

No installation issues for updating the US English version.

Received POP mail and sent a reply, received newsgroup posts and sent a followup. No issues to report.

I do not use the calendar.

CC: (none) => andrewsfarm

Comment 3 Herman Viaene 2024-12-17 11:12:29 CET
MGA9-64 Plasma Wayland on Compaq H000SB
No installation issues with GB and US language packs.
Sending and receiving mails without and with attachment.
Added event to calendar and synched with google calendar, all works OK.

CC: (none) => herman.viaene

Comment 4 Morgan Leijström 2024-12-17 15:05:37 CET
mga9-64 OK

Plasma X11

Repeated tests like I use to perform:

Closed Thunderbird, data backup, updated, started:
Thunderbird just keep working OK:
Opened tabs restored
Settings and local mail kept
Swedish locale
IMAP (offline, IMAP to synk to server)
SMTP
Sent mail with both inline and attached jpg
Received mail with both inline jpg and attached jpg, attached pdf
Viewed attached pdf in Thunderbird, and printed to boomaga and network printer.

I do not use calendar nor tasks or filters.

Similar setup used on two systems, different accounts.

CC: (none) => fri

Comment 5 Guillaume Royer 2024-12-18 14:46:50 CET
MGA 9 64 GNOME

updated with rpms: 

thunderbird-128.5.2-1.mga9
thunderbird-fr-128.5.2-1.mga9

No issues after installation

Calendar and contact synch ok
Send and receive mail with IMAP ok

CC: (none) => guillaume.royer

Comment 6 Thomas Andrews 2024-12-19 01:54:40 CET
Looks OK to me. Validating before they send out another one.

Keywords: (none) => validated_update
Whiteboard: (none) => MGA9-64-OK
CC: (none) => sysadmin-bugs

Comment 7 Jose Manuel López 2024-12-19 08:38:18 CET
Installed in mga9 x64

Works fine for me.

Send and receive ok.
Settings ok.
Spanish translation ok.
Imap and pop3 accounts ok.
Signatures ok.
Local task and calendar ok.
Sync red calendar and task ok.

CC: (none) => Joselp

Comment 8 Mageia Robot 2024-12-21 21:17:39 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0395.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.