{"id":"SUSE-SU-2022:3281-1","summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\nUpdated to Mozilla Thunderbird 102.2.2:\n- CVE-2022-3033: Fixed leaking of sensitive information when composing a response to an HTML email with a META refresh tag (bsc#1203007).\n- CVE-2022-3032: Fixed missing blocking of remote content specified in an HTML document that was nested inside an iframe's srcdoc attribute (bsc#1203007).\n- CVE-2022-3034: Fixed issue where iframe element in an HTML email could trigger a network request (bsc#1203007).\n- CVE-2022-36059: Fixed DoS in Matrix SDK bundled with Thunderbird service attack (bsc#1203007).\n \n- CVE-2022-38472: Fixed Address bar spoofing via XSLT error handling (bsc#1202645).\n- CVE-2022-38473: Fixed cross-origin XSLT Documents inheriting the parent's permissions (bsc#1202645).\n- CVE-2022-38476: Fixed data race and potential use-after-free in PK11_ChangePW (bsc#1202645).\n- CVE-2022-38477: Fixed memory safety bugs (bsc#1202645).\n- CVE-2022-38478: Fixed memory safety bugs (bsc#1202645).\n\n- CVE-2022-36319: Fixed mouse position spoofing with CSS transforms (bsc#1201758).\n- CVE-2022-36318: Fixed directory indexes for bundled resources reflected URL parameters (bsc#1201758).\n- CVE-2022-36314: Fixed unexpected network loads when opening local .lnk files (bsc#1201758).\n- CVE-2022-2505: Fixed memory safety bugs (bsc#1201758).\n\n- CVE-2022-34479: Fixed vulnerability which could overlay the address bar with web content (bsc#1200793).\n- CVE-2022-34470: Fixed use-after-free in nsSHistory (bsc#1200793).\n- CVE-2022-34468: Fixed CSP sandbox header without `allow-scripts` bypass via retargeted javascript (bsc#1200793).\n- CVE-2022-2226: Fixed emails with a mismatching OpenPGP signature date incorrectly accepted as valid (bsc#1200793).\n- CVE-2022-34481: Fixed integer overflow in ReplaceElementsAt (bsc#1200793).\n- CVE-2022-31744: Fixed CSP bypass enabling stylesheet injection (bsc#1200793).\n- CVE-2022-34472: Fixed unavailable PAC file resulting in OCSP requests being blocked (bsc#1200793).\n- CVE-2022-34478: Fixed Microsoft protocols attacks if a user accepts a prompt (bsc#1200793).\n- CVE-2022-2200: Fixed vulnerability where undesired attributes could be set as part of prototype pollution (bsc#1200793).\n- CVE-2022-34484: Fixed memory safety bugs (bsc#1200793).\n","modified":"2026-03-11T07:21:02.664793Z","published":"2022-09-15T13:33:15Z","related":["CVE-2022-2200","CVE-2022-2226","CVE-2022-2505","CVE-2022-3032","CVE-2022-3033","CVE-2022-3034","CVE-2022-31744","CVE-2022-34468","CVE-2022-34470","CVE-2022-34472","CVE-2022-34478","CVE-2022-34479","CVE-2022-34481","CVE-2022-34484","CVE-2022-36059","CVE-2022-36314","CVE-2022-36318","CVE-2022-36319","CVE-2022-38472","CVE-2022-38473","CVE-2022-38476","CVE-2022-38477","CVE-2022-38478"],"upstream":["CVE-2022-2200","CVE-2022-2226","CVE-2022-2505","CVE-2022-3032","CVE-2022-3033","CVE-2022-3034","CVE-2022-31744","CVE-2022-34468","CVE-2022-34470","CVE-2022-34472","CVE-2022-34478","CVE-2022-34479","CVE-2022-34481","CVE-2022-34484","CVE-2022-36059","CVE-2022-36314","CVE-2022-36318","CVE-2022-36319","CVE-2022-38472","CVE-2022-38473","CVE-2022-38476","CVE-2022-38477","CVE-2022-38478"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223281-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1200793"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201758"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202645"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-2200"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-2226"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-2505"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3032"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3033"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3034"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-31744"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-34468"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-34470"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-34472"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-34478"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-34479"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-34481"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-34484"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-36059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-36314"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-36318"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-36319"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-38472"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-38473"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-38476"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-38477"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-38478"}],"affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP3","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.2.2-150200.8.82.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.2.2-150200.8.82.1","MozillaThunderbird-translations-other":"102.2.2-150200.8.82.1","MozillaThunderbird":"102.2.2-150200.8.82.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3281-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP4","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.2.2-150200.8.82.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.2.2-150200.8.82.1","MozillaThunderbird-translations-other":"102.2.2-150200.8.82.1","MozillaThunderbird":"102.2.2-150200.8.82.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3281-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP3","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.2.2-150200.8.82.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.2.2-150200.8.82.1","MozillaThunderbird-translations-other":"102.2.2-150200.8.82.1","MozillaThunderbird":"102.2.2-150200.8.82.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3281-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP4","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.2.2-150200.8.82.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.2.2-150200.8.82.1","MozillaThunderbird-translations-other":"102.2.2-150200.8.82.1","MozillaThunderbird":"102.2.2-150200.8.82.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3281-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.2.2-150200.8.82.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.2.2-150200.8.82.1","MozillaThunderbird-translations-other":"102.2.2-150200.8.82.1","MozillaThunderbird":"102.2.2-150200.8.82.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3281-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.2.2-150200.8.82.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.2.2-150200.8.82.1","MozillaThunderbird-translations-other":"102.2.2-150200.8.82.1","MozillaThunderbird":"102.2.2-150200.8.82.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3281-1.json"}}],"schema_version":"1.7.5"}