{"schema_version":"1.7.3","id":"SUSE-SU-2023:3664-1","published":"2023-09-18T19:50:30Z","modified":"2026-02-04T02:56:48.221278Z","related":["CVE-2023-4051","CVE-2023-4053","CVE-2023-4573","CVE-2023-4574","CVE-2023-4575","CVE-2023-4576","CVE-2023-4577","CVE-2023-4578","CVE-2023-4580","CVE-2023-4581","CVE-2023-4582","CVE-2023-4583","CVE-2023-4584","CVE-2023-4585","CVE-2023-4863"],"upstream":["CVE-2023-4051","CVE-2023-4053","CVE-2023-4573","CVE-2023-4574","CVE-2023-4575","CVE-2023-4576","CVE-2023-4577","CVE-2023-4578","CVE-2023-4580","CVE-2023-4581","CVE-2023-4582","CVE-2023-4583","CVE-2023-4584","CVE-2023-4585","CVE-2023-4863"],"summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\nSecurity fixes:\n\n- Mozilla Thunderbird 115.2.2 (MFSA 2023-40, bsc#1215245)\n  - CVE-2023-4863: Fixed heap buffer overflow in libwebp (bmo#1852649).\n  \n- Mozilla Thunderbird 115.2 (MFSA 2023-38, bsc#1214606)\n  - CVE-2023-4573: Memory corruption in IPC CanvasTranslator (bmo#1846687) \n  - CVE-2023-4574: Memory corruption in IPC ColorPickerShownCallback (bmo#1846688) \n  - CVE-2023-4575: Memory corruption in IPC FilePickerShownCallback (bmo#1846689) \n  - CVE-2023-4576: Integer Overflow in RecordedSourceSurfaceCreation (bmo#1846694) \n  - CVE-2023-4577: Memory corruption in JIT UpdateRegExpStatics (bmo#1847397) \n  - CVE-2023-4051: Full screen notification obscured by file open dialog (bmo#1821884) \n  - CVE-2023-4578: Error reporting methods in SpiderMonkey could have triggered an Out of Memory Exception (bmo#1839007) \n  - CVE-2023-4053: Full screen notification obscured by external program (bmo#1839079) \n  - CVE-2023-4580: Push notifications saved to disk unencrypted (bmo#1843046) \n  - CVE-2023-4581: XLL file extensions were downloadable without warnings (bmo#1843758) \n  - CVE-2023-4582: Buffer Overflow in WebGL glGetProgramiv (bmo#1773874) \n  - CVE-2023-4583: Browsing Context potentially not cleared when closing Private Window (bmo#1842030) \n  - CVE-2023-4584: Memory safety bugs fixed in Firefox 117, Firefox ESR 102.15, Firefox ESR 115.2, Thunderbird 102.15, and Thunderbird 115.2 (bmo#1843968, bmo#1845205, bmo#1846080, bmo#1846526, bmo#1847529) \n  - CVE-2023-4585: Memory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2 (bmo#1751583, bmo#1833504, bmo#1841082, bmo#1847904, bmo#1848999) \n\nOther fixes:\n\nMozilla Thunderbird 115.2.1\n  * new: Column separators are now shown between all columns in\n    tree view (bmo#1847441)\n  * fixed: Crash reporter did not work in Thunderbird Flatpak\n    (bmo#1843102)\n  * fixed: New mail notification always opened message in message\n    pane, even if pane was disabled (bmo#1840092)\n  * fixed: After moving an IMAP message to another folder, the\n    incorrect message was selected in the message list\n    (bmo#1845376)\n  * fixed: Adding a tag to an IMAP message opened in a tab failed\n    (bmo#1844452)\n  * fixed: Junk/Spam folders were not always shown in Unified\n    Folders mode (bmo#1838672)\n  * fixed: Middle-clicking a folder or message did not open it in\n    a background tab, as in previous versions (bmo#1842482)\n  * fixed: Settings tab visual improvements: Advanced Fonts\n    dialog, Section headers hidden behind search box\n    (bmo#1717382,bmo#1846751)\n  * fixed: Various visual and style fixes\n    (bmo#1843707,bmo#1849823)\n  \nMozilla Thunderbird 115.2\n  * new: Thunderbird MSIX packages are now published on\n    archive.mozilla.org (bmo#1817657)\n  * changed: Size, Unread, and Total columns are now right-\n    aligned (bmo#1848604)\n  * changed: Newsgroup names in message list header are now\n    abbreviated (bmo#1833298)\n  * fixed: Message compose window did not apply theme colors to\n    menus (bmo#1845699)\n  * fixed: Reading the second new message in a folder cleared the\n    unread indicator of all other new messages (bmo#1839805)\n  * fixed: Displayed counts of unread or flagged messages could\n    become out-of-sync (bmo#1846860)\n  * fixed: Deleting a message from the context menu with messages\n    sorted in chronological order and smooth scroll enabled\n    caused message list to scroll to top (bmo#1843462)\n  * fixed: Repeatedly switching accounts in Subscribe dialog\n    caused tree view to stop updating (bmo#1845593)\n  * fixed: 'Ignore thread' caused message cards to display\n    incorrectly in message list (bmo#1847966)\n  * fixed: Creating tags from unified toolbar failed\n    (bmo#1846336)\n  * fixed: Cross-folder navigation using F and N did not work\n    (bmo#1845011)\n  * fixed: Account Manager did not resize to fit content, causing\n    'Close' button to become hidden outside bounds of dialog when\n    too many accounts were listed (bmo#1847555)\n  * fixed: Remote content exceptions could not be added in\n    Settings (bmo#1847576)\n  * fixed: Newsgroup list file did not get updated after adding a\n    new NNTP server (bmo#1845464)\n  * fixed: 'Download all headers' option in NNTP 'Download\n    Headers' dialog was incorrectly selected by default\n    (bmo#1845457)\n  * fixed: 'Convert to event/task' was missing from mail context\n    menu (bmo#1817705)\n  * fixed: Events and tasks were not shown in some cases despite\n    being present on remote server (bmo#1827100)\n  * fixed: Various visual and UX improvements\n    (bmo#1844244,bmo#1845645)\n\n- Mozilla Thunderbird 115.1.1\n  * fixed: Some HTML emails printed headers on first page and\n    message on subsequent pages (bmo#1843628)\n  * fixed: Deleting messages from message list sometimes scrolled\n    list to bottom, selecting bottommost message (bmo#1835173)\n  * fixed: Width of icon columns (like Junk or Starred) in\n    message list did not adjust when UI density was changed\n    (bmo#1843014)\n  * fixed: Old OpenPGP secret keys could not be used to decrypt\n    messages under certain circumstances (bmo#1835786)\n  * fixed: When multiple folder modes were active, tab focus\n    navigated through all folder mode options before reaching\n    message list (bmo#1842060)\n  * fixed: Unread message count badge was not displayed on parent\n    folders of subfolder containing unread messages (bmo#1844534)\n  * fixed: 'Undo archive' (via Ctrl-Z) did not un-archive\n    previously archived messages (bmo#1829340)\n  * fixed: 'New' button dropdown menu in 'Message Filters' dialog\n    could not be opened via keyboard navigation (bmo#1843511)\n  * fixed: 'Show New Mail Alert for' input field in 'Customize\n    New Mail Alert' dialog had zero width when using certain\n    language packs (bmo#1845832)\n  * fixed: 'Account Wizard' dialog was too narrow when adding a\n    news server, partially hiding confirmation buttons\n    (bmo#1846588)\n  * fixed: Link Properties and Image Properties dialogs in the\n    composer were too wide (bmo#1816850)\n  * fixed: Thunderbird version number and details in 'About'\n    dialog were not automatically read by screen readers when\n    first opening dialog (bmo#1847078)\n  * fixed: Flatpak improvements and bug fixes\n    (bmo#1825399,bmo#1843094,bmo#1843097)\n  * fixed: Various visual and UX improvements (bmo#1846262)\n","affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP4","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.2.2-150200.8.130.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"115.2.2-150200.8.130.1","MozillaThunderbird-translations-common":"115.2.2-150200.8.130.1","MozillaThunderbird-translations-other":"115.2.2-150200.8.130.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3664-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP5","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.2.2-150200.8.130.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"115.2.2-150200.8.130.1","MozillaThunderbird-translations-common":"115.2.2-150200.8.130.1","MozillaThunderbird-translations-other":"115.2.2-150200.8.130.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3664-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP4","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.2.2-150200.8.130.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"115.2.2-150200.8.130.1","MozillaThunderbird-translations-common":"115.2.2-150200.8.130.1","MozillaThunderbird-translations-other":"115.2.2-150200.8.130.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3664-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP5","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.2.2-150200.8.130.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"115.2.2-150200.8.130.1","MozillaThunderbird-translations-common":"115.2.2-150200.8.130.1","MozillaThunderbird-translations-other":"115.2.2-150200.8.130.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3664-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.2.2-150200.8.130.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"115.2.2-150200.8.130.1","MozillaThunderbird-translations-common":"115.2.2-150200.8.130.1","MozillaThunderbird-translations-other":"115.2.2-150200.8.130.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3664-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.2.2-150200.8.130.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"115.2.2-150200.8.130.1","MozillaThunderbird-translations-common":"115.2.2-150200.8.130.1","MozillaThunderbird-translations-other":"115.2.2-150200.8.130.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3664-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20233664-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214606"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215231"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215245"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4051"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4053"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4573"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4574"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4575"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4576"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4577"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4578"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4580"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4581"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4582"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4583"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4584"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4585"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4863"}]}