{"id":"SUSE-SU-2024:0044-1","summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\nFirefox Extended Support Release 115.6.0 ESR (bsc#1217974):\n\t* CVE-2023-6856: Heap-buffer-overflow affecting WebGL  DrawElementsInstanced method with Mesa VM driver (bmo#1843782).\n\t* CVE-2023-6857: Symlinks may resolve to smaller than expected buffers (bmo#1796023).\n\t* CVE-2023-6858: Heap buffer overflow in nsTextFragment (bmo#1826791).\n\t* CVE-2023-6859: Use-after-free in PR_GetIdentitiesLayer (bmo#1840144).\n\t* CVE-2023-6860: Potential sandbox escape due to VideoBridge lack of texture validation (bmo#1854669).\n\t* CVE-2023-6861: Heap buffer overflow affected nsWindow::PickerOpen(void) in headless mode (bmo#1864118).\n\t* CVE-2023-6862: Use-after-free in nsDNSService (bsc#1868042).\n\t* CVE-2023-6863: Undefined behavior in ShutdownObserver() (bmo#1868901).\n\t* CVE-2023-6864: Memory safety bugs fixed in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6.\n\t* CVE-2023-50762: Truncated signed text was shown with a valid OpenPGP signature (bmo#1862625).\n","modified":"2026-03-11T07:25:36.835958Z","published":"2024-01-07T12:09:57Z","related":["CVE-2023-50761","CVE-2023-50762","CVE-2023-6856","CVE-2023-6857","CVE-2023-6858","CVE-2023-6859","CVE-2023-6860","CVE-2023-6861","CVE-2023-6862","CVE-2023-6863","CVE-2023-6864"],"upstream":["CVE-2023-50761","CVE-2023-50762","CVE-2023-6856","CVE-2023-6857","CVE-2023-6858","CVE-2023-6859","CVE-2023-6860","CVE-2023-6861","CVE-2023-6862","CVE-2023-6863","CVE-2023-6864"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20240044-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-50761"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-50762"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6856"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6858"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6859"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6860"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6861"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6862"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6863"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6864"}],"affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP5","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.6.0-150200.8.142.2"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"115.6.0-150200.8.142.2","MozillaThunderbird-translations-other":"115.6.0-150200.8.142.2","MozillaThunderbird":"115.6.0-150200.8.142.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0044-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP5","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.6.0-150200.8.142.2"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"115.6.0-150200.8.142.2","MozillaThunderbird-translations-other":"115.6.0-150200.8.142.2","MozillaThunderbird":"115.6.0-150200.8.142.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0044-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.6.0-150200.8.142.2"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-other":"115.6.0-150200.8.142.2","MozillaThunderbird":"115.6.0-150200.8.142.2","MozillaThunderbird-translations-common":"115.6.0-150200.8.142.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0044-1.json"}}],"schema_version":"1.7.5"}