{"id":"SUSE-SU-2022:3800-1","summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\n- Mozilla Thunderbird 102.4.0 (bsc#1204421)\n  * changed: Thunderbird will automatically detect and repair OpenPGP key storage corruption caused by using the profile import tool in Thunderbird 102   \n  * fixed: POP message download into a large folder (~13000 messages) caused Thunderbird to temporarily freeze\n  * fixed: Forwarding messages with special characters in Subject failed on Windows\n  * fixed: Links for FileLink attachments were not added when attachment filename contained Unicode characters\n  * fixed: Address Book display pane continued to show contacts after deletion\n  * fixed: Printing address book did not include all contact details\n  * fixed: CardDAV contacts without a Name property did not save to Google Contacts\n  * fixed: 'Publish Calendar' did not work\n  * fixed: Calendar database storage improvements\n  * fixed: Incorrectly handled error responses from CalDAV servers sometimes caused events to disappear from calendar\n  * fixed: Various visual and UX improvements\n- Mozilla Thunderbird 102.3.3\n  * new: Option added to show containing address book for a\n    contact when using `All Address Books` in vertical mode\n    (bmo#1778871)\n  * changed: Thunderbird will try to use POP NTLM authentication\n    even if not advertised by server (bmo#1793349)\n  * changed: Task List and Today Pane sidebars will no longer\n    load when not visible (bmo#1788549)\n  * fixed: Sending a message while a recipient pill was being\n    modified did not save changes (bmo#1779785)\n  * fixed: Nickname column was not available in horizontal view\n    of Address Book (bmo#1778000)\n  * fixed: Multiline organization values were displayed across\n    two columns in horizontal view of Address Book (bmo#1777780)\n  * fixed: Contact vCard fields with multiple values such as\n    Categories were truncated when saved (bmo#1792399)\n  * fixed: ICS calendar files with a `FREEBUSY` property could\n    not be imported (bmo#1783441)\n  * fixed: Thunderbird would hang if calendar event exceeded the\n    year 2035 (bmo#1789999)\n- Mozilla Thunderbird 102.3.2\n  * changed: Thunderbird will try to use POP CRAM-MD5\n    authentication even if not advertised by server (bmo#1789975)\n  * fixed: Checking messages on POP3 accounts caused POP folder\n    to lock if mail server was slow or non-responsive\n    (bmo#1792451)\n  * fixed: Newsgroups named with consecutive dots would not\n    appear when refreshing list of newsgroups (bmo#1787789)\n  * fixed: Sending news articles containing lines starting with\n    dot were sometimes clipped (bmo#1787955)\n  * fixed: CardDAV server sync silently failed if sync token\n    expired (bmo#1791183)\n  * fixed: Contacts from LDAP on macOS address books were not\n    displayed (bmo#1791347)\n  * fixed: Chat account input now accepts URIs for supported chat\n    protocols (bmo#1776706)\n  * fixed: Chat ScreenName field was not migrated to new address\n    book (bmo#1789990)\n  * fixed: Creating a New Event from the Today Pane used the\n    currently selected day from the main calendar instead of from\n    the Today Pane (bmo#1791203)\n  * fixed: `New Event` button in Today Pane was incorrectly\n    disabled sometimes (bmo#1792058)\n  * fixed: Event reminder windows did not close after being\n    dismissed or snoozed (bmo#1791228)\n  * fixed: Improved performance of recurring event date\n    calculation (bmo#1787677)\n  * fixed: Quarterly calendar events on the last day of the month\n    repeated one month early (bmo#1789362)\n  * fixed: Thunderbird would hang if calendar event exceeded the\n    year 2035 (bmo#1789999)\n  * fixed: Whitespace in calendar events was incorrectly handled\n    when upgrading from Thunderbird 91 to 102 (bmo#1790339)\n  * fixed: Various visual and UX improvements (bmo#1755623,bmo#17\n    83903,bmo#1785851,bmo#1786434,bmo#1787286,bmo#1788151,bmo#178\n    9728,bmo#1790499)\n- Mozilla Thunderbird 102.3.1\n  * changed: Compose window encryption options now only appear\n    for encryption technologies that have already been configured\n    (bmo#1788988)\n  * changed: Number of contacts in currently selected address\n    book now displayed at bottom of Address Book list column\n    (bmo#1745571)\n  * fixed: Password prompt did not include server hostname for\n    POP servers (bmo#1786920)\n  * fixed: `Edit Contact` was missing from Contacts sidebar\n    context menus (bmo#1771795)\n  * fixed: Address Book contact lists cut off display of some\n    characters, the result being unreadable (bmo#1780909)\n  * fixed: Menu items for dark-themed alarm dialog were invisible\n    on Windows 7 (bmo#1791738)\n  * fixed: Various security fixes\n  MFSA 2022-43 (bsc#1204411)\n  * CVE-2022-39249 (bmo#1791765)\n    Matrix SDK bundled with Thunderbird vulnerable to an\n    impersonation attack by malicious server administrators\n  * CVE-2022-39250 (bmo#1791765)\n    Matrix SDK bundled with Thunderbird vulnerable to a device\n    verification attack\n  * CVE-2022-39251 (bmo#1791765)\n    Matrix SDK bundled with Thunderbird vulnerable to an\n    impersonation attack\n  * CVE-2022-39236 (bmo#1791765)\n    Matrix SDK bundled with Thunderbird vulnerable to a data\n    corruption issue\n- Mozilla Thunderbird 102.3\n  * changed: Thunderbird will no longer attempt to import account\n    passwords when importing from another Thunderbird profile in\n    order to prevent profile corruption and permanent data loss.\n    (bmo#1790605)\n  * changed: Devtools performance profile will use Thunderbird\n    presets instead of Web Developer presets (bmo#1785954)\n  * fixed: Thunderbird startup performance improvements\n    (bmo#1785967)\n  * fixed: Saving email source and images failed\n    (bmo#1777323,bmo#1778804)\n  * fixed: Error message was shown repeatedly when temporary disk\n    space was full (bmo#1788580)\n  * fixed: Attaching OpenPGP keys without a set size to non-\n    encrypted messages briefly displayed a size of zero bytes\n    (bmo#1788952)\n  * fixed: Global Search entry box initially contained\n    'undefined' (bmo#1780963)\n  * fixed: Delete from POP Server mail filter rule intermittently\n    failed to trigger (bmo#1789418)\n  * fixed: Connections to POP3 servers without UIDL support\n    failed (bmo#1789314)\n  * fixed: Pop accounts with 'Fetch headers only' set downloaded\n    complete messages if server did not advertise TOP capability\n    (bmo#1789356)\n  * fixed: 'File -\u003e New -\u003e Address Book Contact' from Compose\n    window did not work (bmo#1782418)\n  * fixed: Attach 'My vCard' option in compose window was not\n    available (bmo#1787614)\n  * fixed: Improved performance of matching a contact to an email\n    address (bmo#1782725)\n  * fixed: Address book only recognized a contact's first two\n    email addresses (bmo#1777156)\n  * fixed: Address book search and autocomplete failed if a\n    contact vCard could not be parsed (bmo#1789793)\n  * fixed: Downloading NNTP messages for offline use failed\n    (bmo#1785773)\n  * fixed: NNTP client became stuck when connecting to Public-\n    Inbox servers (bmo#1786203)\n  * fixed: Various visual and UX improvements\n    (bmo#1782235,bmo#1787448,bmo#1788725,bmo#1790324)\n  * fixed: Various security fixes\n  * unresolved: No dedicated 'Department' field in address book\n    (bmo#1777780)\n  MFSA 2022-42 (bsc#1203477)\n  * CVE-2022-3266 (bmo#1767360)\n    Out of bounds read when decoding H264\n  * CVE-2022-40959 (bmo#1782211)\n    Bypassing FeaturePolicy restrictions on transient pages\n  * CVE-2022-40960 (bmo#1787633)\n    Data-race when parsing non-UTF-8 URLs in threads\n  * CVE-2022-40958 (bmo#1779993)\n    Bypassing Secure Context restriction for cookies with __Host\n    and __Secure prefix\n  * CVE-2022-40956 (bmo#1770094)\n    Content-Security-Policy base-uri bypass\n  * CVE-2022-40957 (bmo#1777604)\n    Incoherent instruction cache when building WASM on ARM64\n  * CVE-2022-3155 (bmo#1789061)\n    Attachment files saved to disk on macOS could be executed\n    without warning\n  * CVE-2022-40962 (bmo#1776655, bmo#1777574, bmo#1784835,\n    bmo#1785109, bmo#1786502, bmo#1789440)\n    Memory safety bugs fixed in Thunderbird 102.3\n","modified":"2026-03-11T07:21:21.277907Z","published":"2022-10-27T12:59:47Z","related":["CVE-2022-3155","CVE-2022-3266","CVE-2022-39236","CVE-2022-39249","CVE-2022-39250","CVE-2022-39251","CVE-2022-40956","CVE-2022-40957","CVE-2022-40958","CVE-2022-40959","CVE-2022-40960","CVE-2022-40962"],"upstream":["CVE-2022-3155","CVE-2022-3266","CVE-2022-39236","CVE-2022-39249","CVE-2022-39250","CVE-2022-39251","CVE-2022-40956","CVE-2022-40957","CVE-2022-40958","CVE-2022-40959","CVE-2022-40960","CVE-2022-40962"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223800-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203477"},{"type":"REPORT","url":"https://bugzilla.suse.com/1204411"},{"type":"REPORT","url":"https://bugzilla.suse.com/1204421"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3155"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3266"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-39236"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-39249"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-39250"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-39251"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-40956"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-40957"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-40958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-40959"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-40960"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-40962"}],"affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP3","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.4.0-150200.8.85.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.4.0-150200.8.85.1","MozillaThunderbird-translations-other":"102.4.0-150200.8.85.1","MozillaThunderbird":"102.4.0-150200.8.85.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3800-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP4","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.4.0-150200.8.85.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-other":"102.4.0-150200.8.85.1","MozillaThunderbird":"102.4.0-150200.8.85.1","MozillaThunderbird-translations-common":"102.4.0-150200.8.85.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3800-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP3","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.4.0-150200.8.85.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.4.0-150200.8.85.1","MozillaThunderbird-translations-other":"102.4.0-150200.8.85.1","MozillaThunderbird":"102.4.0-150200.8.85.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3800-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP4","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.4.0-150200.8.85.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.4.0-150200.8.85.1","MozillaThunderbird-translations-other":"102.4.0-150200.8.85.1","MozillaThunderbird":"102.4.0-150200.8.85.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3800-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.4.0-150200.8.85.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.4.0-150200.8.85.1","MozillaThunderbird-translations-other":"102.4.0-150200.8.85.1","MozillaThunderbird":"102.4.0-150200.8.85.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3800-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.4.0-150200.8.85.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.4.0-150200.8.85.1","MozillaThunderbird-translations-other":"102.4.0-150200.8.85.1","MozillaThunderbird":"102.4.0-150200.8.85.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3800-1.json"}}],"schema_version":"1.7.5"}