Gentoo Archives: gentoo-announce

From: glsamaker@g.o
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202211-05 ] Mozilla Thunderbird: Multiple Vulnerabilities
Date: Tue, 22 Nov 2022 04:01:15
Message-Id: 166908904801.9.12589517231991027453@2ac734cbf5a7
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202211-05
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: Mozilla Thunderbird: Multiple Vulnerabilities
9 Date: November 22, 2022
10 Bugs: #881407
11 ID: 202211-05
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been discovered in Mozilla Thunderbird,
19 the worst of which could result in arbitrary code execution.
20
21 Background
22 ==========
23
24 Mozilla Thunderbird is a popular open-source email client from the
25 Mozilla project.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 mail-client/thunderbird < 102.5.0 >= 102.5.0
34 2 mail-client/thunderbird-bin < 102.5.0 >= 102.5.0
35
36 Description
37 ===========
38
39 Multiple vulnerabilities have been discovered in Mozilla Thunderbird.
40 Please review the CVE identifiers referenced below for details.
41
42 Impact
43 ======
44
45 Please review the referenced CVE identifiers for details.
46
47 Workaround
48 ==========
49
50 There is no known workaround at this time.
51
52 Resolution
53 ==========
54
55 All Mozilla Thunderbird binary users should upgrade to the latest
56 version:
57
58 # emerge --sync
59 # emerge --ask --oneshot --verbose ">=mail-client/thunderbird-bin-102.5.0"
60
61 All Mozilla Thunderbird users should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot --verbose ">=mail-client/thunderbird-102.5.0"
65
66 References
67 ==========
68
69 [ 1 ] CVE-2022-45403
70 https://nvd.nist.gov/vuln/detail/CVE-2022-45403
71 [ 2 ] CVE-2022-45404
72 https://nvd.nist.gov/vuln/detail/CVE-2022-45404
73 [ 3 ] CVE-2022-45405
74 https://nvd.nist.gov/vuln/detail/CVE-2022-45405
75 [ 4 ] CVE-2022-45406
76 https://nvd.nist.gov/vuln/detail/CVE-2022-45406
77 [ 5 ] CVE-2022-45408
78 https://nvd.nist.gov/vuln/detail/CVE-2022-45408
79 [ 6 ] CVE-2022-45409
80 https://nvd.nist.gov/vuln/detail/CVE-2022-45409
81 [ 7 ] CVE-2022-45410
82 https://nvd.nist.gov/vuln/detail/CVE-2022-45410
83 [ 8 ] CVE-2022-45411
84 https://nvd.nist.gov/vuln/detail/CVE-2022-45411
85 [ 9 ] CVE-2022-45412
86 https://nvd.nist.gov/vuln/detail/CVE-2022-45412
87 [ 10 ] CVE-2022-45416
88 https://nvd.nist.gov/vuln/detail/CVE-2022-45416
89 [ 11 ] CVE-2022-45418
90 https://nvd.nist.gov/vuln/detail/CVE-2022-45418
91 [ 12 ] CVE-2022-45420
92 https://nvd.nist.gov/vuln/detail/CVE-2022-45420
93 [ 13 ] CVE-2022-45421
94 https://nvd.nist.gov/vuln/detail/CVE-2022-45421
95
96 Availability
97 ============
98
99 This GLSA and any updates to it are available for viewing at
100 the Gentoo Security Website:
101
102 https://security.gentoo.org/glsa/202211-05
103
104 Concerns?
105 =========
106
107 Security is a primary focus of Gentoo Linux and ensuring the
108 confidentiality and security of our users' machines is of utmost
109 importance to us. Any security concerns should be addressed to
110 security@g.o or alternatively, you may file a bug at
111 https://bugs.gentoo.org.
112
113 License
114 =======
115
116 Copyright 2022 Gentoo Foundation, Inc; referenced text
117 belongs to its owner(s).
118
119 The contents of this document are licensed under the
120 Creative Commons - Attribution / Share Alike license.
121
122 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature