Mageia 2022-0355: thunderbird security update
Summary
Improperly formed beacon events can disrupt or impede the matrix-js-sdk
from functioning properly(CVE-2022-39236)
Too permissive key forwarding strategy allowing impersonation
(CVE-2022-39249)
Trusting/verifying the user identity under the control of the homeserver
instead of the intended one. (CVE-2022-39250)
Fake to-device messages appearing to originate from another user.
(CVE-2022-39251)
References
- https://bugs.mageia.org/show_bug.cgi?id=30911
- https://www.mozilla.org/en-US/security/advisories/mfsa2022-43/
- https://www.thunderbird.net/en-US/thunderbird/102.3.1/releasenotes/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39236
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39249
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39250
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39251
Resolution
MGASA-2022-0355 - Updated thunderbird packages fix security vulnerability
SRPMS
- 8/core/thunderbird-102.3.1-1.mga8
- 8/core/thunderbird-l10n-102.3.1-1.mga8