RHSA-2023:0819: Important: thunderbird security update
Mozilla Thunderbird is a standalone mail and newsgroup client.This update upgrades Thunderbird to version 102.8.0.Security Fix(es): Mozilla: Content security policy leak in violation reports using iframes (CVE-2023-25728) Mozilla: Screen hijack via browser fullscreen mode (CVE-2023-25730) Mozilla: Potential use-after-free from compartment mismatch in SpiderMonkey (CVE-2023-25735) Mozilla: Invalid downcast in SVGUtils::SetupStrokeGeometry (CVE-2023-25737) Mozilla: Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext (CVE-2023-25739) Mozilla: Fullscreen notification not shown in Firefox Focus (CVE-2023-25743) Mozilla: Memory safety bugs fixed in Firefox 110 and Firefox ESR 102.8 (CVE-2023-25744) Mozilla: Memory safety bugs fixed in Firefox ESR 102.8 (CVE-2023-25746) Mozilla: Extensions could have opened external schemes without user knowledge (CVE-2023-25729) Mozilla: Out of bounds memory write from EncodeInputStream (CVE-2023-25732) Mozilla: User Interface lockup with messages combining S/MIME and OpenPGP (CVE-2023-0616) Mozilla: Web Crypto ImportKey crashes tab (CVE-2023-25742) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_2 - Upgrade
Upgrade
redhat/thunderbird-debuginfoto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_2 - Upgrade
Upgrade
redhat/thunderbird-debugsourceto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_2 - Upgrade
Upgrade
thunderbirdto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_2 - Upgrade
Upgrade
thunderbird (x86_64)to a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_2 - Upgrade
Upgrade
thunderbird (ppc64le)to a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_2
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0819?
The severity of RHSA-2023:0819 is classified as a moderate security issue.
How do I fix RHSA-2023:0819?
To fix RHSA-2023:0819, update Thunderbird to version 102.8.0-2.el8_2.
What vulnerabilities are addressed in RHSA-2023:0819?
RHSA-2023:0819 addresses a content security policy leak and a screen hijack vulnerability.
What versions of Thunderbird are affected by RHSA-2023:0819?
RHSA-2023:0819 affects multiple versions of Thunderbird prior to 102.8.0-2.el8_2.
Is there a recommended action for users of Thunderbird?
Users of Thunderbird should prioritize upgrading to the latest version to mitigate the vulnerabilities in RHSA-2023:0819.