{"id":"SUSE-SU-2024:3507-1","summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\n- Mozilla Thunderbird 128.2.3\n  MFSA 2024-43 (bsc#1229821)\n  * CVE-2024-8394: Crash when aborting verification of OTR chat.\n  * CVE-2024-8385: WASM type confusion involving ArrayTypes.\n  * CVE-2024-8381: Type confusion when looking up a property name in a 'with' block.\n  * CVE-2024-8382: Internal event interfaces were exposed to web content when browser EventHandler listener callbacks\n    ran.\n  * CVE-2024-8384: Garbage collection could mis-color cross-compartment objects in OOM conditions.\n  * CVE-2024-8386: SelectElements could be shown over another site if popups are allowed.\n  * CVE-2024-8387: Memory safety bugs fixed in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2.\n  MFSA 2024-37 (bsc#1228648)\n  * CVE-2024-7518: Fullscreen notification dialog can be obscured by document content.\n  * CVE-2024-7519: Out of bounds memory access in graphics shared memory handling.\n  * CVE-2024-7520: Type confusion in WebAssembly.\n  * CVE-2024-7521: Incomplete WebAssembly exception handing.\n  * CVE-2024-7522: Out of bounds read in editor component.\n  * CVE-2024-7525: Missing permission check when creating a StreamFilter.\n  * CVE-2024-7526: Uninitialized memory used by WebGL.\n  * CVE-2024-7527: Use-after-free in JavaScript garbage collection.\n  * CVE-2024-7528: Use-after-free in IndexedDB.\n  * CVE-2024-7529: Document content could partially obscure security prompts.\n  MFSA 2024-32 (bsc#1226316)\n  * CVE-2024-6606: Out-of-bounds read in clipboard component.\n  * CVE-2024-6607: Leaving pointerlock by pressing the escape key could be prevented.\n  * CVE-2024-6608: Cursor could be moved out of the viewport using pointerlock.\n  * CVE-2024-6609: Memory corruption in NSS.\n  * CVE-2024-6610: Form validation popups could block exiting full-screen mode.\n  * CVE-2024-6600: Memory corruption in WebGL API.\n  * CVE-2024-6601: Race condition in permission assignment.\n  * CVE-2024-6602: Memory corruption in NSS.\n  * CVE-2024-6603: Memory corruption in thread creation.\n  * CVE-2024-6611: Incorrect handling of SameSite cookies.\n  * CVE-2024-6612: CSP violation leakage when using devtools.\n  * CVE-2024-6613: Incorrect listing of stack frames.\n  * CVE-2024-6614: Incorrect listing of stack frames.\n  * CVE-2024-6604: Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, Thunderbird 128, and Thunderbird\n    115.13.\n  * CVE-2024-6615: Memory safety bugs fixed in Firefox 128 and Thunderbird 128.\n  \nBug fixes:\n- Recommend libfido2-udev in order to try to get security keys (e.g. Yubikeys) working out of the box. (bsc#1184272)\n","modified":"2026-03-11T07:27:25.720220Z","published":"2024-10-01T15:02:17Z","related":["CVE-2024-6600","CVE-2024-6601","CVE-2024-6602","CVE-2024-6603","CVE-2024-6604","CVE-2024-6606","CVE-2024-6607","CVE-2024-6608","CVE-2024-6609","CVE-2024-6610","CVE-2024-6611","CVE-2024-6612","CVE-2024-6613","CVE-2024-6614","CVE-2024-6615","CVE-2024-7518","CVE-2024-7519","CVE-2024-7520","CVE-2024-7521","CVE-2024-7522","CVE-2024-7525","CVE-2024-7526","CVE-2024-7527","CVE-2024-7528","CVE-2024-7529","CVE-2024-8381","CVE-2024-8382","CVE-2024-8384","CVE-2024-8385","CVE-2024-8386","CVE-2024-8387","CVE-2024-8394"],"upstream":["CVE-2024-6600","CVE-2024-6601","CVE-2024-6602","CVE-2024-6603","CVE-2024-6604","CVE-2024-6606","CVE-2024-6607","CVE-2024-6608","CVE-2024-6609","CVE-2024-6610","CVE-2024-6611","CVE-2024-6612","CVE-2024-6613","CVE-2024-6614","CVE-2024-6615","CVE-2024-7518","CVE-2024-7519","CVE-2024-7520","CVE-2024-7521","CVE-2024-7522","CVE-2024-7525","CVE-2024-7526","CVE-2024-7527","CVE-2024-7528","CVE-2024-7529","CVE-2024-8381","CVE-2024-8382","CVE-2024-8384","CVE-2024-8385","CVE-2024-8386","CVE-2024-8387","CVE-2024-8394"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20243507-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184272"},{"type":"REPORT","url":"https://bugzilla.suse.com/1226316"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228648"},{"type":"REPORT","url":"https://bugzilla.suse.com/1229821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6600"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6601"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6602"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6603"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6604"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6606"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6607"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6608"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6609"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6610"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6611"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6612"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6613"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6614"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6615"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7518"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7519"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7520"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7521"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7522"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7525"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7526"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7527"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7528"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7529"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-8381"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-8382"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-8384"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-8385"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-8386"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-8387"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-8394"}],"affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP5","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"128.2.3-150200.8.177.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"128.2.3-150200.8.177.1","MozillaThunderbird-translations-other":"128.2.3-150200.8.177.1","MozillaThunderbird":"128.2.3-150200.8.177.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:3507-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP6","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"128.2.3-150200.8.177.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"128.2.3-150200.8.177.1","MozillaThunderbird-translations-common":"128.2.3-150200.8.177.1","MozillaThunderbird-translations-other":"128.2.3-150200.8.177.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:3507-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP5","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"128.2.3-150200.8.177.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"128.2.3-150200.8.177.1","MozillaThunderbird-translations-other":"128.2.3-150200.8.177.1","MozillaThunderbird":"128.2.3-150200.8.177.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:3507-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP6","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"128.2.3-150200.8.177.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"128.2.3-150200.8.177.1","MozillaThunderbird-translations-other":"128.2.3-150200.8.177.1","MozillaThunderbird":"128.2.3-150200.8.177.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:3507-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"128.2.3-150200.8.177.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-other":"128.2.3-150200.8.177.1","MozillaThunderbird":"128.2.3-150200.8.177.1","MozillaThunderbird-translations-common":"128.2.3-150200.8.177.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:3507-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"128.2.3-150200.8.177.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"128.2.3-150200.8.177.1","MozillaThunderbird-translations-other":"128.2.3-150200.8.177.1","MozillaThunderbird":"128.2.3-150200.8.177.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:3507-1.json"}}],"schema_version":"1.7.5"}