RHSA-2023:0822: Important: thunderbird security update
Mozilla Thunderbird is a standalone mail and newsgroup client.This update upgrades Thunderbird to version 102.8.0.Security Fix(es): Mozilla: Content security policy leak in violation reports using iframes (CVE-2023-25728) Mozilla: Screen hijack via browser fullscreen mode (CVE-2023-25730) Mozilla: Potential use-after-free from compartment mismatch in SpiderMonkey (CVE-2023-25735) Mozilla: Invalid downcast in SVGUtils::SetupStrokeGeometry (CVE-2023-25737) Mozilla: Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext (CVE-2023-25739) Mozilla: Fullscreen notification not shown in Firefox Focus (CVE-2023-25743) Mozilla: Memory safety bugs fixed in Firefox 110 and Firefox ESR 102.8 (CVE-2023-25744) Mozilla: Memory safety bugs fixed in Firefox ESR 102.8 (CVE-2023-25746) Mozilla: Extensions could have opened external schemes without user knowledge (CVE-2023-25729) Mozilla: Out of bounds memory write from EncodeInputStream (CVE-2023-25732) Mozilla: User Interface lockup with messages combining S/MIME and OpenPGP (CVE-2023-0616) Mozilla: Web Crypto ImportKey crashes tab (CVE-2023-25742) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_6 - Upgrade
Upgrade
redhat/thunderbird-debuginfoto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_6 - Upgrade
Upgrade
redhat/thunderbird-debugsourceto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_6 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_6.aa - Upgrade
Upgrade
redhat/thunderbird-debuginfoto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_6.aa - Upgrade
Upgrade
redhat/thunderbird-debugsourceto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_6.aa - Upgrade
Upgrade
thunderbirdto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_6
Event History
Frequently Asked Questions
What are the security issues addressed in RHSA-2023:0822?
RHSA-2023:0822 addresses content security policy leaks and screen hijacking vulnerabilities in Mozilla Thunderbird 102.8.0.
What versions of Thunderbird are impacted by RHSA-2023:0822?
RHSA-2023:0822 affects all versions of Thunderbird prior to 102.8.0.
How do I fix the vulnerabilities listed in RHSA-2023:0822?
To fix the vulnerabilities in RHSA-2023:0822, upgrade to Mozilla Thunderbird version 102.8.0 or later.
Is RHSA-2023:0822 a critical update?
RHSA-2023:0822 is a security update that addresses significant vulnerabilities; applying it promptly is recommended.
Where can I find more details about RHSA-2023:0822?
Detailed information regarding RHSA-2023:0822 can be found in the Red Hat security advisory.