{"id":"SUSE-SU-2022:4579-1","summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\nUpdate to version 102.6 (bsc#1206242):\n\n- CVE-2022-46880: Use-after-free in WebGL\n- CVE-2022-46872: Arbitrary file read from a compromised content process\n- CVE-2022-46881: Memory corruption in WebGL\n- CVE-2022-46874: Drag and Dropped Filenames could have been truncated to malicious extensions\n- CVE-2022-46875: Download Protections were bypassed by .atloc and .ftploc files on Mac OS\n- CVE-2022-46882: Use-after-free in WebGL\n- CVE-2022-46878: Memory safety bugs fixed in Thunderbird 102.6\n","modified":"2026-03-11T07:21:52.706858Z","published":"2022-12-20T07:33:14Z","related":["CVE-2022-46872","CVE-2022-46874","CVE-2022-46875","CVE-2022-46878","CVE-2022-46880","CVE-2022-46881","CVE-2022-46882"],"upstream":["CVE-2022-46872","CVE-2022-46874","CVE-2022-46875","CVE-2022-46878","CVE-2022-46880","CVE-2022-46881","CVE-2022-46882"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20224579-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1206242"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-46872"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-46874"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-46875"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-46878"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-46880"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-46881"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-46882"}],"affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP4","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.6.0-150200.8.96.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.6.0-150200.8.96.1","MozillaThunderbird-translations-other":"102.6.0-150200.8.96.1","MozillaThunderbird":"102.6.0-150200.8.96.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4579-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP4","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.6.0-150200.8.96.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"102.6.0-150200.8.96.1","MozillaThunderbird-translations-common":"102.6.0-150200.8.96.1","MozillaThunderbird-translations-other":"102.6.0-150200.8.96.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4579-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.6.0-150200.8.96.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.6.0-150200.8.96.1","MozillaThunderbird-translations-other":"102.6.0-150200.8.96.1","MozillaThunderbird":"102.6.0-150200.8.96.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4579-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.6.0-150200.8.96.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.6.0-150200.8.96.1","MozillaThunderbird-translations-other":"102.6.0-150200.8.96.1","MozillaThunderbird":"102.6.0-150200.8.96.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4579-1.json"}}],"schema_version":"1.7.5"}