{"schema_version":"1.7.3","id":"SUSE-SU-2021:4150-1","published":"2021-12-22T09:58:04Z","modified":"2026-02-04T04:13:49.237449Z","related":["CVE-2021-29981","CVE-2021-29982","CVE-2021-29987","CVE-2021-29991","CVE-2021-32810","CVE-2021-38492","CVE-2021-38493","CVE-2021-38495","CVE-2021-38496","CVE-2021-38497","CVE-2021-38498","CVE-2021-38500","CVE-2021-38501","CVE-2021-38502","CVE-2021-38503","CVE-2021-38504","CVE-2021-38505","CVE-2021-38506","CVE-2021-38507","CVE-2021-38508","CVE-2021-38509","CVE-2021-38510","CVE-2021-40529","CVE-2021-43528","CVE-2021-43536","CVE-2021-43537","CVE-2021-43538","CVE-2021-43539","CVE-2021-43541","CVE-2021-43542","CVE-2021-43543","CVE-2021-43545","CVE-2021-43546"],"upstream":["CVE-2021-29981","CVE-2021-29982","CVE-2021-29987","CVE-2021-29991","CVE-2021-32810","CVE-2021-38492","CVE-2021-38493","CVE-2021-38495","CVE-2021-38496","CVE-2021-38497","CVE-2021-38498","CVE-2021-38500","CVE-2021-38501","CVE-2021-38502","CVE-2021-38503","CVE-2021-38504","CVE-2021-38505","CVE-2021-38506","CVE-2021-38507","CVE-2021-38508","CVE-2021-38509","CVE-2021-38510","CVE-2021-40529","CVE-2021-43528","CVE-2021-43536","CVE-2021-43537","CVE-2021-43538","CVE-2021-43539","CVE-2021-43541","CVE-2021-43542","CVE-2021-43543","CVE-2021-43545","CVE-2021-43546"],"summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\n- Update to version 91.4 MFSA 2021-54 (bsc#1193485)\n- CVE-2021-43536: URL leakage when navigating while executing asynchronous function\n- CVE-2021-43537: Heap buffer overflow when using structured clone\n- CVE-2021-43538: Missing fullscreen and pointer lock notification when requesting both\n- CVE-2021-43539: GC rooting failure when calling wasm instance methods\n- CVE-2021-43541: External protocol handler parameters were unescaped\n- CVE-2021-43542: XMLHttpRequest error codes could have leaked the existence of an external protocol handler\n- CVE-2021-43543: Bypass of CSP sandbox directive when embedding\n- CVE-2021-43545: Denial of Service when using the Location API in a loop\n- CVE-2021-43546: Cursor spoofing could overlay user interface when native cursor is zoomed\n- CVE-2021-43528: JavaScript unexpectedly enabled for the composition area\n\n- Update to version 91.3.2\n- CVE-2021-40529: Fixed ElGamal implementation could allow plaintext recovery (bsc#1190244)\n\n- Update to version 91.3 MFSA 2021-50 (bsc#1192250)\n- CVE-2021-38503: Fixed iframe sandbox rules did not apply to XSLT stylesheets\n- CVE-2021-38504: Fixed use-after-free in file picker dialog\n- CVE-2021-38505: Fixed Windows 10 Cloud Clipboard may have recorded sensitive user data\n- CVE-2021-38506: Fixed Thunderbird could be coaxed into going into fullscreen mode without notification or warning\n- CVE-2021-38507: Fixed opportunistic Encryption in HTTP2 could be used to bypass the Same-Origin-Policy on services hosted on other ports\n- CVE-2021-38508: Fixed permission Prompt could be overlaid, resulting in user confusion and potential spoofing\n- CVE-2021-38509: Fixed Javascript alert box could have been spoofed onto an arbitrary domain\n- CVE-2021-38510: Fixed Download Protections were bypassed by .inetloc files on Mac OS\n- Fixed plain text reformatting regression (bsc#1182863)\n\n- Update to version 91.2 MFSA 2021-47 (bsc#1191332)\n- CVE-2021-29981: Live range splitting could have led to conflicting assignments in the JIT\n- CVE-2021-29982: Single bit data leak due to incorrect JIT optimization and type confusion\n- CVE-2021-29987: Users could have been tricked into accepting unwanted permissions on Linux\n- CVE-2021-32810: Data race in crossbeam-deque\n- CVE-2021-38493: Memory safety bugs fixed in Thunderbird 78.14 and Thunderbird 91.1\n- CVE-2021-38496: Use-after-free in MessageTask\n- CVE-2021-38497: Validation message could have been overlaid on another origin\n- CVE-2021-38498: Use-after-free of nsLanguageAtomService object\n- CVE-2021-38500: Memory safety bugs fixed in Thunderbird 91.2\n- CVE-2021-38501: Memory safety bugs fixed in Thunderbird 91.2\n- CVE-2021-38502: Downgrade attack on SMTP STARTTLS connections\n\n- Update to version 91.1.0 MFSA 2021-41 (bsc#1190269)\n- CVE-2021-38492: Navigating to `mk:` URL scheme could load Internet Explorer\n- CVE-2021-38495: Memory safety bugs fixed in Thunderbird 91.1\n\n- Update to version 91.0.1 MFSA 2021-37 (bsc#1189547)\n- CVE-2021-29991: Header Splitting possible with HTTP/3 Responses\n","affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP2","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"91.4.0-8.45.2"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"91.4.0-8.45.2","MozillaThunderbird-translations-common":"91.4.0-8.45.2","MozillaThunderbird-translations-other":"91.4.0-8.45.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:4150-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP3","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"91.4.0-8.45.2"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"91.4.0-8.45.2","MozillaThunderbird-translations-common":"91.4.0-8.45.2","MozillaThunderbird-translations-other":"91.4.0-8.45.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:4150-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-20214150-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1182863"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189547"},{"type":"REPORT","url":"https://bugzilla.suse.com/1190244"},{"type":"REPORT","url":"https://bugzilla.suse.com/1190269"},{"type":"REPORT","url":"https://bugzilla.suse.com/1191332"},{"type":"REPORT","url":"https://bugzilla.suse.com/1192250"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193485"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29981"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29982"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29991"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32810"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38492"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38493"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38495"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38496"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38497"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38498"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38500"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38501"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38503"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38504"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38505"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38506"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38507"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38508"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38509"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-38510"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-40529"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-43528"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-43536"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-43537"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-43538"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-43539"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-43541"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-43542"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-43543"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-43545"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-43546"}]}