First published: Mon Feb 20 2023(Updated: )
Mozilla Thunderbird is a standalone mail and newsgroup client.<br>This update upgrades Thunderbird to version 102.8.0.<br>Security Fix(es):<br><li> Mozilla: Content security policy leak in violation reports using iframes (CVE-2023-25728)</li> <li> Mozilla: Screen hijack via browser fullscreen mode (CVE-2023-25730)</li> <li> Mozilla: Potential use-after-free from compartment mismatch in SpiderMonkey (CVE-2023-25735)</li> <li> Mozilla: Invalid downcast in SVGUtils::SetupStrokeGeometry (CVE-2023-25737)</li> <li> Mozilla: Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext (CVE-2023-25739)</li> <li> Mozilla: Fullscreen notification not shown in Firefox Focus (CVE-2023-25743)</li> <li> Mozilla: Memory safety bugs fixed in Firefox 110 and Firefox ESR 102.8 (CVE-2023-25744)</li> <li> Mozilla: Memory safety bugs fixed in Firefox ESR 102.8 (CVE-2023-25746)</li> <li> Mozilla: Extensions could have opened external schemes without user knowledge (CVE-2023-25729)</li> <li> Mozilla: Out of bounds memory write from EncodeInputStream (CVE-2023-25732)</li> <li> Mozilla: User Interface lockup with messages combining S/MIME and OpenPGP (CVE-2023-0616)</li> <li> Mozilla: Web Crypto ImportKey crashes tab (CVE-2023-25742)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/thunderbird | <102.8.0-2.el7_9 | 102.8.0-2.el7_9 |
redhat/thunderbird | <102.8.0-2.el7_9 | 102.8.0-2.el7_9 |
redhat/thunderbird-debuginfo | <102.8.0-2.el7_9 | 102.8.0-2.el7_9 |
redhat/thunderbird | <102.8.0-2.el7_9 | 102.8.0-2.el7_9 |
redhat/thunderbird-debuginfo | <102.8.0-2.el7_9 | 102.8.0-2.el7_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.