{"schema_version":"1.7.3","id":"SUSE-SU-2020:3935-1","published":"2020-12-25T08:26:55Z","modified":"2026-02-04T02:48:44.871519Z","related":["CVE-2020-16042","CVE-2020-26970","CVE-2020-26971","CVE-2020-26973","CVE-2020-26974","CVE-2020-26978","CVE-2020-35111","CVE-2020-35112","CVE-2020-35113"],"upstream":["CVE-2020-16042","CVE-2020-26970","CVE-2020-26971","CVE-2020-26973","CVE-2020-26974","CVE-2020-26978","CVE-2020-35111","CVE-2020-35112","CVE-2020-35113"],"summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\n- Mozilla Thunderbird 78.6\n  * new: MailExtensions: Added\n    browser.windows.openDefaultBrowser() (bmo#1664708)\n  * changed: Thunderbird now only shows quota exceeded\n    indications on the main window (bmo#1671748)\n  * changed: MailExtensions: menus API enabled in messages being\n    composed (bmo#1670832)\n  * changed: MailExtensions: Honor allowScriptsToClose argument\n    in windows.create API function (bmo#1675940)\n  * changed: MailExtensions: APIs that returned an accountId will\n    reflect the account the message belongs to, not what is\n    stored in message headers (bmo#1644032)\n  * fixed: Keyboard shortcut for toggling message 'read' status\n    not shown in menus (bmo#1619248)\n  * fixed: OpenPGP: After importing a secret key, Key Manager\n    displayed properties of the wrong key (bmo#1667054)\n  * fixed: OpenPGP: Inline PGP parsing improvements (bmo#1660041)\n  * fixed: OpenPGP: Discovering keys online via Key Manager\n    sometimes failed on Linux (bmo#1634053)\n  * fixed: OpenPGP: Encrypted attachment 'Decrypt and Open/Save\n    As' did not work (bmo#1663169)\n  * fixed: OpenPGP: Importing keys failed on macOS (bmo#1680757)\n  * fixed: OpenPGP: Verification of clear signed UTF-8 text\n    failed (bmo#1679756)\n  * fixed: Address book: Some columns incorrectly displayed no\n    data (bmo#1631201)\n  * fixed: Address book: The address book view did not update\n    after changing the name format in the menu (bmo#1678555)\n  * fixed: Calendar: Could not import an ICS file into a CalDAV\n    calendar (bmo#1652984)\n  * fixed: Calendar: Two 'Home' calendars were visible on a new\n    profile (bmo#1656782)\n  * fixed: Calendar: Dark theme was incomplete on Linux\n    (bmo#1655543)\n  * fixed: Dark theme did not apply to new mail notification\n    popups (bmo#1681083)\n  * fixed: Folder icon, message list, and contact side bar visual\n    improvements (bmo#1679436)\n  * fixed: MailExtensions: HTTP refresh in browser content tabs\n    did not work (bmo#1667774)\n  * fixed: MailExtensions: messageDisplayScripts failed to run in\n    main window (bmo#1674932)\n  * fixed: Various security fixes\n  MFSA 2020-56 (bsc#1180039)\n  * CVE-2020-16042 (bmo#1679003)\n    Operations on a BigInt could have caused uninitialized memory\n    to be exposed\n  * CVE-2020-26971 (bmo#1663466)\n    Heap buffer overflow in WebGL\n  * CVE-2020-26973 (bmo#1680084)\n    CSS Sanitizer performed incorrect sanitization\n  * CVE-2020-26974 (bmo#1681022)\n    Incorrect cast of StyleGenericFlexBasis resulted in a heap\n    use-after-free\n  * CVE-2020-26978 (bmo#1677047)\n    Internal network hosts could have been probed by a malicious\n    webpage\n  * CVE-2020-35111 (bmo#1657916)\n    The proxy.onRequest API did not catch view-source URLs\n  * CVE-2020-35112 (bmo#1661365)\n    Opening an extension-less download may have inadvertently\n    launched an executable instead\n  * CVE-2020-35113 (bmo#1664831, bmo#1673589)\n    Memory safety bugs fixed in Thunderbird 78.6\n\nMozilla Thunderbird 78.5.1\n\n* new: OpenPGP: Added option to disable email subject\n  encryption (bmo#1666073)\n* changed: OpenPGP public key import now supports multi-file\n  selection and bulk accepting imported keys (bmo#1665145)\n* changed: MailExtensions: getComposeDetails will wait for\n  'compose-editor-ready' event (bmo#1675012)\n* fixed: New mail icon was not removed from the system tray at\n  shutdown (bmo#1664586)\n* fixed: 'Place replies in the folder of the message being\n  replied to' did not work when using 'Reply to List'\n  (bmo#522450)\n* fixed: Thunderbird did not honor the 'Run search on server'\n  option when searching messages (bmo#546925)\n* fixed: Highlight color for folders with unread messages\n  wasn't visible in dark theme (bmo#1676697)\n* fixed: OpenPGP: Key were missing from Key Manager\n  (bmo#1674521)\n* fixed: OpenPGP: Option to import keys from clipboard always\n  disabled (bmo#1676842)\n* fixed: The 'Link' button on the large attachments info bar\n  failed to open up Filelink section in Options if the user had\n  not yet configured Filelink (bmo#1677647)\n* fixed: Address book: Printing members of a mailing list\n  resulted in incorrect output (bmo#1676859)\n* fixed: Unable to connect to LDAP servers configured with a\n  self-signed SSL certificate (bmo#1659947)\n* fixed: Autoconfig via LDAP did not work as expected\n  (bmo#1662433)\n* fixed: Calendar: Pressing Ctrl-Enter in the new event dialog\n  would create duplicate events (bmo#1668478)\n* fixed: Various security fixes\n\nMFSA 2020-53 (bsc#1179530)\n* CVE-2020-26970 (bmo#1677338)\n  Stack overflow due to incorrect parsing of SMTP server\n  response codes\n","affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP2","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"78.6.0-8.3.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"78.6.0-8.3.1","MozillaThunderbird-translations-common":"78.6.0-8.3.1","MozillaThunderbird-translations-other":"78.6.0-8.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:3935-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2020/suse-su-20203935-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179530"},{"type":"REPORT","url":"https://bugzilla.suse.com/1180039"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-16042"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-26970"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-26971"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-26973"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-26974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-26978"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-35111"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-35112"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-35113"}]}