Mageia 2022-0428: thunderbird security update
Summary
Service Workers might have learned size of cross-origin media files.
(CVE-2022-45403)
Fullscreen notification bypass. (CVE-2022-45404)
Use-after-free in InputStream implementation. (CVE-2022-45405)
Use-after-free of a JavaScript Realm. (CVE-2022-45406)
Fullscreen notification bypass via windowName. (CVE-2022-45408)
Use-after-free in Garbage Collection. (CVE-2022-45409)
ServiceWorker-intercepted requests bypassed SameSite cookie policy.
(CVE-2022-45410)
Cross-Site Tracing was possible via non-standard override headers.
(CVE-2022-45411)
Symlinks may resolve to partially uninitialized buffers. (CVE-2022-45412)
Keystroke Side-Channel Leakage. (CVE-2022-45416)
Custom mouse cursor could have been drawn over browser UI. (CVE-2022-45418)
Iframe contents could be rendered outside the iframe. (CVE-2022-45420)
Memory safety bugs fixed in Thunderbird 102.5. (CVE-2022-45421)
References
- https://bugs.mageia.org/show_bug.cgi?id=31131
- https://www.thunderbird.net/en-US/thunderbird/102.5.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2022-49/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45403
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45404
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45405
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45406
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45408
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45409
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45410
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45411
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45412
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45416
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45418
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45420
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45421
Resolution
MGASA-2022-0428 - Updated thunderbird packages fix security vulnerability
SRPMS
- 8/core/thunderbird-102.5.0-1.mga8
- 8/core/thunderbird-l10n-102.5.0-1.mga8