RHSA-2023:0820: Important: thunderbird security update
Mozilla Thunderbird is a standalone mail and newsgroup client.This update upgrades Thunderbird to version 102.8.0.Security Fix(es): Mozilla: Content security policy leak in violation reports using iframes (CVE-2023-25728) Mozilla: Screen hijack via browser fullscreen mode (CVE-2023-25730) Mozilla: Potential use-after-free from compartment mismatch in SpiderMonkey (CVE-2023-25735) Mozilla: Invalid downcast in SVGUtils::SetupStrokeGeometry (CVE-2023-25737) Mozilla: Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext (CVE-2023-25739) Mozilla: Fullscreen notification not shown in Firefox Focus (CVE-2023-25743) Mozilla: Memory safety bugs fixed in Firefox 110 and Firefox ESR 102.8 (CVE-2023-25744) Mozilla: Memory safety bugs fixed in Firefox ESR 102.8 (CVE-2023-25746) Mozilla: Extensions could have opened external schemes without user knowledge (CVE-2023-25729) Mozilla: Out of bounds memory write from EncodeInputStream (CVE-2023-25732) Mozilla: User Interface lockup with messages combining S/MIME and OpenPGP (CVE-2023-0616) Mozilla: Web Crypto ImportKey crashes tab (CVE-2023-25742) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_4 - Upgrade
Upgrade
redhat/thunderbird-debuginfoto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_4 - Upgrade
Upgrade
redhat/thunderbird-debugsourceto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_4 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_4.aa - Upgrade
Upgrade
redhat/thunderbird-debuginfoto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_4.aa - Upgrade
Upgrade
redhat/thunderbird-debugsourceto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_4.aa - Upgrade
Upgrade
thunderbirdto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_4
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0820?
The severity of RHSA-2023:0820 is classified as moderate due to the potential information leak and security risks associated with its vulnerabilities.
How do I fix RHSA-2023:0820?
To fix RHSA-2023:0820, update Thunderbird to version 102.8.0-2.el8_4 as specified in the advisory.
What vulnerabilities are addressed in RHSA-2023:0820?
RHSA-2023:0820 addresses vulnerabilities including a content security policy leak in violation reports using iframes and potential screen hijacking.
Which versions of Thunderbird are affected by RHSA-2023:0820?
Thunderbird versions prior to 102.8.0-2.el8_4 are affected by RHSA-2023:0820.
Is there any other action required after updating for RHSA-2023:0820?
After updating for RHSA-2023:0820, it is recommended to review security settings and verify the integrity of additional add-ons and configurations.