{"id":"SUSE-SU-2022:1176-1","summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\n- Updated to version 91.8 (bsc#1197903):\n  - CVE-2022-1097: Fixed a memory corruption issue with NSSToken objects.\n  - CVE-2022-28281: Fixed a memory corruption issue due to unexpected WebAuthN\n    Extensions.\n  - CVE-2022-1197: Fixed an issue where OpenPGP revocation information was ignored.\n  - CVE-2022-1196: Fixed a memory corruption issue after VR process destruction.\n  - CVE-2022-28282: Fixed a memory corruption issue in document translation.\n  - CVE-2022-28285: Fixed a memory corruption issue in JIT code generation.\n  - CVE-2022-28286: Fixed an iframe layout issue that could have been exploited\n    to stage spoofing attacks.\n  - CVE-2022-24713: Fixed a potential denial of service via complex regular\n    expressions.\n  - CVE-2022-28289: Fixed multiple memory corruption issues.\n\nNon-security fixes:\n\n- Changed Google accounts using password authentication to use OAuth2.\n- Fixed an issue where OpenPGP ECC keys created by Thunderbird could not be\n  imported into GnuPG.\n- Fixed an issue where exporting multiple public PGP keys from Thunderbird\n  was not possible.\n- Fixed an issue where replying to a newsgroup message erroneously displayed\n  a 'No-reply' popup warning.\n- Fixed an issue with opening older address books.\n- Fixed an issue where LDAP directories would be lost when switching to\n  'Offline' mode.\n- Fixed an issue when importing webcals.\n","modified":"2026-03-11T07:18:49.427688Z","published":"2022-04-13T10:15:53Z","related":["CVE-2022-1097","CVE-2022-1196","CVE-2022-1197","CVE-2022-24713","CVE-2022-28281","CVE-2022-28282","CVE-2022-28285","CVE-2022-28286","CVE-2022-28289"],"upstream":["CVE-2022-1097","CVE-2022-1196","CVE-2022-1197","CVE-2022-24713","CVE-2022-28281","CVE-2022-28282","CVE-2022-28285","CVE-2022-28286","CVE-2022-28289"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20221176-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1197903"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1097"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1196"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1197"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-24713"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-28281"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-28282"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-28285"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-28286"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-28289"}],"affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP3","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"91.8.0-150200.8.65.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"91.8.0-150200.8.65.1","MozillaThunderbird-translations-other":"91.8.0-150200.8.65.1","MozillaThunderbird":"91.8.0-150200.8.65.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1176-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP4","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"91.8.0-150200.8.65.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"91.8.0-150200.8.65.1","MozillaThunderbird-translations-other":"91.8.0-150200.8.65.1","MozillaThunderbird":"91.8.0-150200.8.65.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1176-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP3","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"91.8.0-150200.8.65.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"91.8.0-150200.8.65.1","MozillaThunderbird-translations-other":"91.8.0-150200.8.65.1","MozillaThunderbird":"91.8.0-150200.8.65.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1176-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"91.8.0-150200.8.65.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"91.8.0-150200.8.65.1","MozillaThunderbird-translations-common":"91.8.0-150200.8.65.1","MozillaThunderbird-translations-other":"91.8.0-150200.8.65.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1176-1.json"}}],"schema_version":"1.7.5"}