Security update for MozillaThunderbird
Announcement ID: | SUSE-SU-2024:4050-1 |
---|---|
Release Date: | 2024-11-25T15:37:50Z |
Rating: | critical |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves 11 vulnerabilities can now be installed.
Description:
This update for MozillaThunderbird fixes the following issues:
- Mozilla Thunderbird 128.4.3
- fixed: Folder corruption could cause Thunderbird to freeze and become unusable
- fixed: Message corruption could be propagated when reading mbox
- fixed: Folder compaction was not abandoned on shutdown
- fixed: Folder compaction did not clean up on failure
- fixed: Collapsed NNTP thread incorrectly indicated there were unread messages
- fixed: Navigating to next unread message did not wait for all messages to be loaded
- fixed: Applying column view to folder and children could break if folder error occurred
- fixed: Remote content notifications were broken with encrypted messages
- fixed: Updating criteria of a saved search resulted in poor search performance
- fixed: Drop-downs may not work in some places
- fixed: Security fixes MFSA 2024-61 (bsc#1233355)
-
CVE-2024-11159 Potential disclosure of plaintext in OpenPGP encrypted message
-
Mozilla Thunderbird 128.4.2
- changed: Increased the auto-compaction threshold to reduce frequency of compaction
- fixed: New profile creation caused console errors
- fixed: Repair folder could result in older messages showing wrong date and time
- fixed: Recently deleted messages could become undeleted if message compaction failed
- fixed: Visual and UX improvements
- fixed: Clicking on an HTML button could cause Thunderbird to freeze
- fixed: Messages could not be selected for dragging
- fixed: Could not open attached file in a MIME encrypted message
- fixed: Account creation "Setup Documentation" link was broken
- fixed: Unable to generate QR codes when exporting to mobile in some cases
- fixed: Operating system reauthentication was missing when exporting QR codes for mobile
-
fixed: Could not drag all-day events from one day to another in week view
-
Mozilla Thunderbird 128.4.1
-
new: Add the 20 year donation appeal
-
Mozilla Thunderbird 128.4
- new: Export Thunderbird account settings to Thunderbird Mobile via QRCode
- fixed: Unable to send an unencrypted response to an OpenPGP encrypted message
- fixed: Thunderbird update did not update language pack version until another restart
- fixed: Security fixes MFSA 2024-58 (bsc#1231879)
- CVE-2024-10458 Permission leak via embed or object elements
- CVE-2024-10459 Use-after-free in layout with accessibility
- CVE-2024-10460 Confusing display of origin for external protocol handler prompt
- CVE-2024-10461 XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response
- CVE-2024-10462 Origin of permission prompt could be spoofed by long URL
- CVE-2024-10463 Cross origin video frame leak
- CVE-2024-10464 History interface could have been used to cause a Denial of Service condition in the browser
- CVE-2024-10465 Clipboard "paste" button persisted across tabs
- CVE-2024-10466 DOM push subscription message could hang Firefox
- CVE-2024-10467 Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
openSUSE Leap 15.5
zypper in -t patch openSUSE-SLE-15.5-2024-4050=1
-
openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2024-4050=1
-
SUSE Package Hub 15 15-SP5
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-4050=1
-
SUSE Package Hub 15 15-SP6
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-4050=1
-
SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4
zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-4050=1
-
SUSE Linux Enterprise Workstation Extension 15 SP5
zypper in -t patch SUSE-SLE-Product-WE-15-SP5-2024-4050=1
-
SUSE Linux Enterprise Workstation Extension 15 SP6
zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2024-4050=1
Package List:
-
openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)
- MozillaThunderbird-debuginfo-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-other-128.4.3-150200.8.188.1
- MozillaThunderbird-debugsource-128.4.3-150200.8.188.1
- MozillaThunderbird-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-common-128.4.3-150200.8.188.1
-
openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
- MozillaThunderbird-debuginfo-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-other-128.4.3-150200.8.188.1
- MozillaThunderbird-debugsource-128.4.3-150200.8.188.1
- MozillaThunderbird-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-common-128.4.3-150200.8.188.1
-
SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x)
- MozillaThunderbird-debuginfo-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-other-128.4.3-150200.8.188.1
- MozillaThunderbird-debugsource-128.4.3-150200.8.188.1
- MozillaThunderbird-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-common-128.4.3-150200.8.188.1
-
SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x)
- MozillaThunderbird-debuginfo-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-other-128.4.3-150200.8.188.1
- MozillaThunderbird-debugsource-128.4.3-150200.8.188.1
- MozillaThunderbird-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-common-128.4.3-150200.8.188.1
-
SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (x86_64)
- MozillaThunderbird-debuginfo-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-other-128.4.3-150200.8.188.1
- MozillaThunderbird-debugsource-128.4.3-150200.8.188.1
- MozillaThunderbird-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-common-128.4.3-150200.8.188.1
-
SUSE Linux Enterprise Workstation Extension 15 SP5 (x86_64)
- MozillaThunderbird-debuginfo-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-other-128.4.3-150200.8.188.1
- MozillaThunderbird-debugsource-128.4.3-150200.8.188.1
- MozillaThunderbird-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-common-128.4.3-150200.8.188.1
-
SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64)
- MozillaThunderbird-debuginfo-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-other-128.4.3-150200.8.188.1
- MozillaThunderbird-debugsource-128.4.3-150200.8.188.1
- MozillaThunderbird-128.4.3-150200.8.188.1
- MozillaThunderbird-translations-common-128.4.3-150200.8.188.1
References:
- https://www.suse.com/security/cve/CVE-2024-10458.html
- https://www.suse.com/security/cve/CVE-2024-10459.html
- https://www.suse.com/security/cve/CVE-2024-10460.html
- https://www.suse.com/security/cve/CVE-2024-10461.html
- https://www.suse.com/security/cve/CVE-2024-10462.html
- https://www.suse.com/security/cve/CVE-2024-10463.html
- https://www.suse.com/security/cve/CVE-2024-10464.html
- https://www.suse.com/security/cve/CVE-2024-10465.html
- https://www.suse.com/security/cve/CVE-2024-10466.html
- https://www.suse.com/security/cve/CVE-2024-10467.html
- https://www.suse.com/security/cve/CVE-2024-11159.html
- https://bugzilla.suse.com/show_bug.cgi?id=1231879
- https://bugzilla.suse.com/show_bug.cgi?id=1233355