Updated thunderbird packages fix security vulnerability
Publication date: 01 Oct 2022Modification date: 01 Oct 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-39236 , CVE-2022-39249 , CVE-2022-39250 , CVE-2022-39251
Description
Improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly(CVE-2022-39236) Too permissive key forwarding strategy allowing impersonation (CVE-2022-39249) Trusting/verifying the user identity under the control of the homeserver instead of the intended one. (CVE-2022-39250) Fake to-device messages appearing to originate from another user. (CVE-2022-39251)
References
- https://bugs.mageia.org/show_bug.cgi?id=30911
- https://www.mozilla.org/en-US/security/advisories/mfsa2022-43/
- https://www.thunderbird.net/en-US/thunderbird/102.3.1/releasenotes/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39236
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39249
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39250
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39251
SRPMS
8/core
- thunderbird-102.3.1-1.mga8
- thunderbird-l10n-102.3.1-1.mga8