🛡️ SUSE-SU-2023:3664-1 — mozillathunderbird (CVE-2023-4863 +14 more)
Description
Security update for MozillaThunderbird
This update for MozillaThunderbird fixes the following issues:
Security fixes:
- Mozilla Thunderbird 115.2.2 (MFSA 2023-40, bsc#1215245)
- CVE-2023-4863: Fixed heap buffer overflow in libwebp (bmo#1852649).
- Mozilla Thunderbird 115.2 (MFSA 2023-38, bsc#1214606)
- CVE-2023-4573: Memory corruption in IPC CanvasTranslator (bmo#1846687)
- CVE-2023-4574: Memory corruption in IPC ColorPickerShownCallback (bmo#1846688)
- CVE-2023-4575: Memory corruption in IPC FilePickerShownCallback (bmo#1846689)
- CVE-2023-4576: Integer Overflow in RecordedSourceSurfaceCreation (bmo#1846694)
- CVE-2023-4577: Memory corruption in JIT UpdateRegExpStatics (bmo#1847397)
- CVE-2023-4051: Full screen notification obscured by file open dialog (bmo#1821884)
- CVE-2023-4578: Error reporting methods in SpiderMonkey could have triggered an Out of Memory Exception (bmo#1839007)
- CVE-2023-4053: Full screen notification obscured by external program (bmo#1839079)
- CVE-2023-4580: Push notifications saved to disk unencrypted (bmo#1843046)
- CVE-2023-4581: XLL file extensions were downloadable without warnings (bmo#1843758)
- CVE-2023-4582: Buffer Overflow in WebGL glGetProgramiv (bmo#1773874)
- CVE-2023-4583: Browsing Context potentially not cleared when closing Private Window (bmo#1842030)
- CVE-2023-4584: Memory safety bugs fixed in Firefox 117, Firefox ESR 102.15, Firefox ESR 115.2, Thunderbird 102.15, and Thunderbird 115.2 (bmo#1843968, bmo#1845205, bmo#1846080, bmo#1846526, bmo#1847529)
- CVE-2023-4585: Memory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2 (bmo#1751583, bmo#1833504, bmo#1841082, bmo#1847904, bmo#1848999)
Other fixes:
Mozilla Thunderbird 115.2.1
- new: Column separators are now shown between all columns in
tree view (bmo#1847441)
- fixed: Crash reporter did not work in Thunderbird Flatpak
(bmo#1843102)
- fixed: New mail notification always opened message in message
pane, even if pane was disabled (bmo#1840092)
- fixed: After moving an IMAP message to another folder, the
incorrect message was selected in the message list
(bmo#1845376)
- fixed: Adding a tag to an IMAP message opened in a tab failed
(bmo#1844452)
- fixed: Junk/Spam folders were not always shown in Unified
Folders mode (bmo#1838672)
- fixed: Middle-clicking a folder or message did not open it in
a background tab, as in previous versions (bmo#1842482)
- fixed: Settings tab visual improvements: Advanced Fonts
dialog, Section headers hidden behind search box
(bmo#1717382,bmo#1846751)
- fixed: Various visual and style fixes
(bmo#1843707,bmo#1849823)
Mozilla Thunderbird 115.2
- new: Thunderbird MSIX packages are now published on
archive.mozilla.org (bmo#1817657)
- changed: Size, Unread, and Total columns are now right-
aligned (bmo#1848604)
- changed: Newsgroup names in message list header are now
abbreviated (bmo#1833298)
- fixed: Message compose window did not apply theme colors to
menus (bmo#1845699)
- fixed: Reading the second new message in a folder cleared the
unread indicator of all other new messages (bmo#1839805)
- fixed: Displayed counts of unread or flagged messages could
become out-of-sync (bmo#1846860)
- fixed: Deleting a message from the context menu with messages
sorted in chronological order and smooth scroll enabled
caused message list to scroll to top (bmo#1843462)
- fixed: Repeatedly switching accounts in Subscribe dialog
caused tree view to stop updating (bmo#1845593)
- fixed: 'Ignore thread' caused message cards to display
incorrectly in message list (bmo#1847966)
- fixed: Creating tags from unified toolbar failed
(bmo#1846336)
- fixed: Cross-folder navigation using F and N did not work
(bmo#1845011)
- fixed: Account Manager did not resize to fit content, causing
'Close' button to become hidden outside bounds of dialog when
too many accounts were listed (bmo#1847555)
- fixed: Remote content exceptions could not be added in
Settings (bmo#1847576)
- fixed: Newsgroup list file did not get updated after adding a
new NNTP server (bmo#1845464)
- fixed: 'Download all headers' option in NNTP 'Download
Headers' dialog was incorrectly selected by default
(bmo#1845457)
- fixed: 'Convert to event/task' was missing from mail context
menu (bmo#1817705)
- fixed: Events and tasks were not shown in some cases despite
being present on remote server (bmo#1827100)
- fixed: Various visual and UX improvements
(bmo#1844244,bmo#1845645)
- Mozilla Thunderbird 115.1.1
- fixed: Some HTML emails printed headers on first page and
message on subsequent pages (bmo#1843628)
- fixed: Deleting messages from message list sometimes scrolled
list to bottom, selecting bottommost message (bmo#1835173)
- fixed: Width of icon columns (like Junk or Starred) in
message
Affected software
SUSE-SU-2023:3664-1 is recorded against 1 package.
- mozillathunderbird (fixed in 115.2.2-150200.8.130.1)
Timeline and source
Published on 18 September 2023 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| mozillathunderbird | — | 115.2.2-150200.8.130.1 |
References
Similar Threats
- Unknown openSUSE-SU-2024:10230-1
- Unknown openSUSE-SU-2024:10601-1
- Unknown openSUSE-SU-2024:11571-1
- Unknown openSUSE-SU-2024:11607-1
- Unknown openSUSE-SU-2024:11698-1
Free Vulnerability Check
Is your site affected by SUSE-SU-2023:3664-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2023:3664-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.