🛡️ SUSE-SU-2023:3664-1 — mozillathunderbird (CVE-2023-4863 +14 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for MozillaThunderbird

This update for MozillaThunderbird fixes the following issues:

Security fixes:

  • Mozilla Thunderbird 115.2.2 (MFSA 2023-40, bsc#1215245)
  • CVE-2023-4863: Fixed heap buffer overflow in libwebp (bmo#1852649).
  • Mozilla Thunderbird 115.2 (MFSA 2023-38, bsc#1214606)
  • CVE-2023-4573: Memory corruption in IPC CanvasTranslator (bmo#1846687)
  • CVE-2023-4574: Memory corruption in IPC ColorPickerShownCallback (bmo#1846688)
  • CVE-2023-4575: Memory corruption in IPC FilePickerShownCallback (bmo#1846689)
  • CVE-2023-4576: Integer Overflow in RecordedSourceSurfaceCreation (bmo#1846694)
  • CVE-2023-4577: Memory corruption in JIT UpdateRegExpStatics (bmo#1847397)
  • CVE-2023-4051: Full screen notification obscured by file open dialog (bmo#1821884)
  • CVE-2023-4578: Error reporting methods in SpiderMonkey could have triggered an Out of Memory Exception (bmo#1839007)
  • CVE-2023-4053: Full screen notification obscured by external program (bmo#1839079)
  • CVE-2023-4580: Push notifications saved to disk unencrypted (bmo#1843046)
  • CVE-2023-4581: XLL file extensions were downloadable without warnings (bmo#1843758)
  • CVE-2023-4582: Buffer Overflow in WebGL glGetProgramiv (bmo#1773874)
  • CVE-2023-4583: Browsing Context potentially not cleared when closing Private Window (bmo#1842030)
  • CVE-2023-4584: Memory safety bugs fixed in Firefox 117, Firefox ESR 102.15, Firefox ESR 115.2, Thunderbird 102.15, and Thunderbird 115.2 (bmo#1843968, bmo#1845205, bmo#1846080, bmo#1846526, bmo#1847529)
  • CVE-2023-4585: Memory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2 (bmo#1751583, bmo#1833504, bmo#1841082, bmo#1847904, bmo#1848999)

Other fixes:

Mozilla Thunderbird 115.2.1

  • new: Column separators are now shown between all columns in

tree view (bmo#1847441)

  • fixed: Crash reporter did not work in Thunderbird Flatpak

(bmo#1843102)

  • fixed: New mail notification always opened message in message

pane, even if pane was disabled (bmo#1840092)

  • fixed: After moving an IMAP message to another folder, the

incorrect message was selected in the message list

(bmo#1845376)

  • fixed: Adding a tag to an IMAP message opened in a tab failed

(bmo#1844452)

  • fixed: Junk/Spam folders were not always shown in Unified

Folders mode (bmo#1838672)

  • fixed: Middle-clicking a folder or message did not open it in

a background tab, as in previous versions (bmo#1842482)

  • fixed: Settings tab visual improvements: Advanced Fonts

dialog, Section headers hidden behind search box

(bmo#1717382,bmo#1846751)

  • fixed: Various visual and style fixes

(bmo#1843707,bmo#1849823)

Mozilla Thunderbird 115.2

  • new: Thunderbird MSIX packages are now published on

archive.mozilla.org (bmo#1817657)

  • changed: Size, Unread, and Total columns are now right-

aligned (bmo#1848604)

  • changed: Newsgroup names in message list header are now

abbreviated (bmo#1833298)

  • fixed: Message compose window did not apply theme colors to

menus (bmo#1845699)

  • fixed: Reading the second new message in a folder cleared the

unread indicator of all other new messages (bmo#1839805)

  • fixed: Displayed counts of unread or flagged messages could

become out-of-sync (bmo#1846860)

  • fixed: Deleting a message from the context menu with messages

sorted in chronological order and smooth scroll enabled

caused message list to scroll to top (bmo#1843462)

  • fixed: Repeatedly switching accounts in Subscribe dialog

caused tree view to stop updating (bmo#1845593)

  • fixed: 'Ignore thread' caused message cards to display

incorrectly in message list (bmo#1847966)

  • fixed: Creating tags from unified toolbar failed

(bmo#1846336)

  • fixed: Cross-folder navigation using F and N did not work

(bmo#1845011)

  • fixed: Account Manager did not resize to fit content, causing

'Close' button to become hidden outside bounds of dialog when

too many accounts were listed (bmo#1847555)

  • fixed: Remote content exceptions could not be added in

Settings (bmo#1847576)

  • fixed: Newsgroup list file did not get updated after adding a

new NNTP server (bmo#1845464)

  • fixed: 'Download all headers' option in NNTP 'Download

Headers' dialog was incorrectly selected by default

(bmo#1845457)

  • fixed: 'Convert to event/task' was missing from mail context

menu (bmo#1817705)

  • fixed: Events and tasks were not shown in some cases despite

being present on remote server (bmo#1827100)

  • fixed: Various visual and UX improvements

(bmo#1844244,bmo#1845645)

  • Mozilla Thunderbird 115.1.1
  • fixed: Some HTML emails printed headers on first page and

message on subsequent pages (bmo#1843628)

  • fixed: Deleting messages from message list sometimes scrolled

list to bottom, selecting bottommost message (bmo#1835173)

  • fixed: Width of icon columns (like Junk or Starred) in

message

Affected software

SUSE-SU-2023:3664-1 is recorded against 1 package.

  • mozillathunderbird (fixed in 115.2.2-150200.8.130.1)

Timeline and source

Published on 18 September 2023 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2023-09-18
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
mozillathunderbird 115.2.2-150200.8.130.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2023:3664-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2023:3664-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2023