{"id":"SUSE-SU-2023:1736-1","summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\nMFSA 2023-12 (bsc#1209953):\n\n- CVE-2023-28427: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack (bmo#1822595)\n\nMFSA 2023-11 (bsc#1209173):\n\n- CVE-2023-25751: Incorrect code generation during JIT compilation (bmo#1814899).\n- CVE-2023-28164: URL being dragged from a removed cross-origin iframe into the same tab triggered navigation (bmo#1809122).\n- CVE-2023-28162: Invalid downcast in Worklets (bmo#1811327).\n- CVE-2023-25752: Potential out-of-bounds when accessing throttled streams (bmo#1811627).\n- CVE-2023-28163: Windows Save As dialog resolved environment variables (bmo#1817768)\n- CVE-2023-28176: Memory safety bugs fixed in Thunderbird 102.9 (bmo#1808352, bmo#1811637, bmo#1815904, bmo#1817442, bmo#1818674).\n  \nMozilla Thunderbird 102.9:\n  \n- fixed: Notification about a sender's changed OpenPGP key was not immediately visible (bmo#1814003)\n- fixed: TLS Certificate Override dialog did not appear when retrieving messages via IMAP using 'Get Messages' context menu (bmo#1816596)\n- fixed: Spellcheck dictionaries were missing from localized Thunderbird builds that should have included them (bmo#1818257)\n- fixed: Tooltips for 'Show/Hide' calendar toggle did not display (bmo#1809557)\n- fixed: Various security fixes  \n    \nMozilla Thunderbird 102.9.1:\n\n- fixed: Thunderbird was unable to open file URLs from command line (URLs beginning with 'file://') (bmo#1816343)\n- fixed: Source strings for localized builds not uploaded to FTP as expected (bmo#1817086)\n- fixed: Visual and theme improvements (bmo#1821358, bmo#1822286)\n- fixed: Security fixes\n","modified":"2026-03-11T07:22:48.355147Z","published":"2023-04-03T11:12:58Z","related":["CVE-2023-25751","CVE-2023-25752","CVE-2023-28162","CVE-2023-28163","CVE-2023-28164","CVE-2023-28176","CVE-2023-28427"],"upstream":["CVE-2023-25751","CVE-2023-25752","CVE-2023-28162","CVE-2023-28163","CVE-2023-28164","CVE-2023-28176","CVE-2023-28427"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20231736-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209173"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209953"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-25751"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-25752"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28162"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28163"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28164"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28176"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28427"}],"affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP4","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.9.1-150200.8.110.2"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"102.9.1-150200.8.110.2","MozillaThunderbird-translations-other":"102.9.1-150200.8.110.2","MozillaThunderbird":"102.9.1-150200.8.110.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1736-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP4","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.9.1-150200.8.110.2"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-other":"102.9.1-150200.8.110.2","MozillaThunderbird":"102.9.1-150200.8.110.2","MozillaThunderbird-translations-common":"102.9.1-150200.8.110.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1736-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.9.1-150200.8.110.2"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"102.9.1-150200.8.110.2","MozillaThunderbird-translations-common":"102.9.1-150200.8.110.2","MozillaThunderbird-translations-other":"102.9.1-150200.8.110.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1736-1.json"}}],"schema_version":"1.7.5"}