Path: ...!npeer.as286.net!npeer-ng0.as286.net!fu-berlin.de!news.servidellagleba.it!bofh.it!news.nic.it!robomod From: Moritz Muehlenhoff Newsgroups: linux.debian.announce.security Subject: [SECURITY] [DSA 5355-1] thunderbird security update Date: Sat, 18 Feb 2023 20:00:01 +0100 Message-ID: X-Original-To: debian-security-announce@lists.debian.org X-Mailbox-Line: From debian-security-announce-request@lists.debian.org Sat Feb 18 18:55:25 2023 Old-Return-Path: X-Amavis-Spam-Status: No, score=-116.191 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DIGITS_LETTERS=1, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FVGT_m_MULTI_ODD=0.02, LDO_WHITELIST=-5, PGPSIGNATURE=-5, RCVD_IN_DNSWL_HI=-5, USER_IN_DKIM_WELCOMELIST=-0.01, USER_IN_DKIM_WHITELIST=-100] autolearn=ham autolearn_force=no Old-Dkim-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=g5RNjmtsfzMlGAVAPqwGTU4zfaHA30euA86We62CCHA=; b=VM CemEb+HwmldB0SESgmKWzDg0G90bjuImMYY1BcsFgCzLlLQ6VfsXIwr23sWFJB8jhvgVP5fXGcUfK QTiYeXDWSfPT95vZ0Se7ie3zihTAFq+T1ePGFAuxHn9MlRZ/xpWzfLQcJwOB/GVY1Xe4k35/qPtnE jwvv+4mO27F8hn84pl/zit8EJ4PJoEgjHfDeiOjt4VA6v/yJHAwQRN3jBgFvq4miBSkg/61Ul7BE/ LxcksIhu9rVS+9F1znqjnH/94eDsAoFLDn+J6MtIORzQGs1tW6qzom9BVcXcefZyi0WephOt39zMl j8h1MEqkLNaXW7hAWs/qLKnk1bBt8w5w==; MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline X-Debian: PGP check passed for security officers Priority: urgent Reply-To: debian-security-announce-request@lists.debian.org X-Mailing-List: archive/latest/4255 List-ID: List-URL: List-Archive: https://lists.debian.org/msgid-search/Y/EfBsOhTYFjdPtY@seger.debian.org Approved: robomod@news.nic.it Lines: 49 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Sat, 18 Feb 2023 18:55:02 +0000 X-Original-Message-ID: Bytes: 4789 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5355-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff February 18, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : thunderbird CVE ID : CVE-2022-46871 CVE-2022-46877 CVE-2023-0430 CVE-2023-0616 CVE-2023-0767 CVE-2023-23598 CVE-2023-23601 CVE-2023-23602 CVE-2023-23603 CVE-2023-23605 CVE-2023-25728 CVE-2023-25729 CVE-2023-25730 CVE-2023-25732 CVE-2023-25735 CVE-2023-25737 CVE-2023-25739 CVE-2023-25742 CVE-2023-25744 CVE-2023-25746 Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the stable distribution (bullseye), these problems have been fixed in version 1:102.8.0-1~deb11u1. We recommend that you upgrade your thunderbird packages. For the detailed security status of thunderbird please refer to its security tracker page at: https://security-tracker.debian.org/tracker/thunderbird Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmPxHdcACgkQEMKTtsN8 TjYnMQ/+KN+lldOJMw1DFjHQ2jpZ3wEjJVPUm1JX1mMB1KSyHjexuCatHom9HPuv IqUW9ag9aAwsvoNGenGiUdImhltn87+/f5VASEAeywp60+EUfsPzMfvukQekVaem aHOFXnvhR8CLxi3kFmN5xjBS6aFqOkCRHlBoM8PtKw7IRiqHk1gkX0mZ2uWrBRZf IZq8fE6LyJxDxnl5MArCBOVIGgpnKi06Fuz7Ekd3z8dGfFZgWxERudPcfMVT+zd5 6F8w0KpWwR4JHzPyurgYEXdrGlXY++rkQmcH1tjkFVrXD9QsvBYniPLulEX6Tkyu TxtGDWJguFu4IWKpNNwP6Cmrhw2+n4jBZLqqpfgHGtr1MvxPI59w7/ZVAfkKGtJZ LF2ubFN+GN80dwX0+FIfIqHHr5CUuVKMKT5WFy03LQcOMc5G68A3WRLVvhxEdcEx Fb3yOagWp8HMHeYhPZhnxNJBZ4Isu6zPhTpjQLiUEljI1nTyBFKA6ivd9emxQIHm oALSSlNHtdzuQkSENBnIAzCFzZpuz5aPSUElnx3e1HZQfeTySiAu3/LH6nPjTQQV JPXHIbyJpIu/L+5W3W5FXlm3chwqkaV1Lg9TQaG87bHd3dlQbRWT5BNVfVn5nlwS 2Bbwbf2Cg9kS/hY9FJoWhuO+b7+hpH2jkt1X7LdrRpHKTAGm2No= =L3Gu -----END PGP SIGNATURE-----