{"affected":[{"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"115.1.0-150200.8.127.1","MozillaThunderbird-translations-common":"115.1.0-150200.8.127.1","MozillaThunderbird-translations-other":"115.1.0-150200.8.127.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP4","name":"MozillaThunderbird","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"115.1.0-150200.8.127.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"115.1.0-150200.8.127.1","MozillaThunderbird-translations-common":"115.1.0-150200.8.127.1","MozillaThunderbird-translations-other":"115.1.0-150200.8.127.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP5","name":"MozillaThunderbird","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"115.1.0-150200.8.127.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"115.1.0-150200.8.127.1","MozillaThunderbird-translations-common":"115.1.0-150200.8.127.1","MozillaThunderbird-translations-other":"115.1.0-150200.8.127.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP4","name":"MozillaThunderbird","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"115.1.0-150200.8.127.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"115.1.0-150200.8.127.1","MozillaThunderbird-translations-common":"115.1.0-150200.8.127.1","MozillaThunderbird-translations-other":"115.1.0-150200.8.127.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP5","name":"MozillaThunderbird","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"115.1.0-150200.8.127.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"115.1.0-150200.8.127.1","MozillaThunderbird-translations-common":"115.1.0-150200.8.127.1","MozillaThunderbird-translations-other":"115.1.0-150200.8.127.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.4","name":"MozillaThunderbird","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"115.1.0-150200.8.127.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"115.1.0-150200.8.127.1","MozillaThunderbird-translations-common":"115.1.0-150200.8.127.1","MozillaThunderbird-translations-other":"115.1.0-150200.8.127.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.5","name":"MozillaThunderbird","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.5"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"115.1.0-150200.8.127.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for MozillaThunderbird fixes the following issues:\n\nUpdate Mozilla Thunderbird 115.1.0 (bsc#1213746):\n\n- CVE-2023-4045: Fixed cross-origin restrictions bypass with Offscreen Canvas (bmo#1833876).\n- CVE-2023-4046: Fixed incorrect value used during WASM compilation (bmo#1837686).\n- CVE-2023-4047: Fixed potential permissions request bypass via clickjacking (bmo#1839073).\n- CVE-2023-4048: Fixed crash in DOMParser due to out-of-memory conditions (bmo#1841368).\n- CVE-2023-4049: Fixed potential race conditions when releasing platform objects (bmo#1842658).\n- CVE-2023-4050: Fixed stack buffer overflow in StorageManager (bmo#1843038).\n- CVE-2023-4052: Fixed file deletion and privilege escalation through Firefox uninstaller (bmo#1824420).\n- CVE-2023-4054: Fixed lack of warning when opening appref-ms files (bmo#1840777).\n- CVE-2023-4055: Fixed cookie jar overflow caused unexpected cookie jar state (bmo#1782561).\n- CVE-2023-4056: Fixed memory safety bugs (bmo#1820587, bmo#1824634, bmo#1839235, bmo#1842325, bmo#1843847).\n- CVE-2023-4057: Fixed memory safety bugs (bmo#1841682).\n\nBugfixes:\n\n- Remove bashisms from startup-script (bsc#1213657).\n","id":"SUSE-SU-2023:3228-1","modified":"2023-08-08T11:54:49Z","published":"2023-08-08T11:54:49Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20233228-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213657"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213746"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4045"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4046"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4047"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4048"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4049"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4050"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4054"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4055"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4056"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4057"}],"related":["CVE-2023-4045","CVE-2023-4046","CVE-2023-4047","CVE-2023-4048","CVE-2023-4049","CVE-2023-4050","CVE-2023-4052","CVE-2023-4054","CVE-2023-4055","CVE-2023-4056","CVE-2023-4057"],"summary":"Security update for MozillaThunderbird","upstream":["CVE-2023-4045","CVE-2023-4046","CVE-2023-4047","CVE-2023-4048","CVE-2023-4049","CVE-2023-4050","CVE-2023-4052","CVE-2023-4054","CVE-2023-4055","CVE-2023-4056","CVE-2023-4057"]}