Der kostenlose Mailclient für Windows, MacOS und Linux, Thunderbird, erhielt das Bugfix Release 102.2.0. Das Update schließt 5 Sicherheitslücken, bringt neue Features und behebt Fehler.
Thunderbird 102.2.0 Security Notes
AnnouncedAugust 23, 2022ImpacthighProductsThunderbirdFixed in
- Thunderbird 102.2
In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
#CVE-2022-38472: Address bar spoofing via XSLT error handling
ReporterArmin EbertImpacthigh
Description
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin.
References
#CVE-2022-38473: Cross-origin XSLT Documents would have inherited the parent’s permissions
ReporterArmin EbertImpacthigh
Description
A cross-origin iframe referencing an XSLT document would inherit the parent domain’s permissions (such as microphone or camera access).
References
#CVE-2022-38476: Data race and potential use-after-free in PK11_ChangePW
ReporterMarian LazaImpactlow
Description
A data race could occur in the PK11_ChangePW
function, potentially leading to a use-after-free vulnerability. In Thunderbird, this lock protected the data when a user changed their master password.
References
#CVE-2022-38477: Memory safety bugs fixed in Thunderbird 102.2
ReporterMozilla developers and communityImpacthigh
Description
Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
References
#CVE-2022-38478: Memory safety bugs fixed in Thunderbird 102.2, and Thunderbird 91.13
ReporterMozilla developers and communityImpacthigh
Description
Members the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.1 and Thunderbird 91.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
References
Thunderbird Release Notes
WHAT’S NEW
CHANGES
Thunderbird on macOS will now prompt for Primary Password on startup if set
Thunderbird will no longer offer to import OpenPGP keys that are incomplete
Selecting or unselecting a dictionary in the Spelling
compose toolbar button will no longer immediately close the menu; Making dictionary changes via the editor context menu will continue to close the context menu
Contact address lines are now adjusted to appear in the expected order
Custom1-4 fields restored to Address Book UI; existing data is preserved from pre-102 profiles
FIXES
Thunderbird startup performance improvements
ALT+<numpad digits>
keypress events were intercepted by the Spaces Toolbar, preventing special character entry on Windows
Searching on attachment status did not work in Message Search dialog
Repairing IMAP folders in Offline mode removed local copy of the folders
POP3 message download progress bar was not displayed
POP Fetch headers only
mode did not work for some server configurations
POP accounts using GSSAPI or NTLM authentication were not able to log into the server
A TLS certificate override dialog for self-signed certificates was not shown for IMAP accounts
Saving attachments from newsgroups did not work
Setting contact type to „None“ was not possible if a type was previously set
Editing a contact without Name fields populated filled in the email address into the name fields
Address book toolbar buttons were not keyboard accessible
Auto-detection of CalDAV and CardDAV via DNS records used server domain leading to failures
Various visual and theme improvements
Various security fixes
KNOWN ISSUES
„Get Map“ feature missing from address book for physical addresses
No dedicated „Department“ field in address book
Quelle: Thunderbird — Release Notes (102.2.0) — Thunderbird
Interessiert in verschiedenste IT Themen, schreibe ich in diesem Blog über Software, Hardware, Smart Home, Games und vieles mehr. Ich berichte z.B. über die Installation und Konfiguration von Software als auch von Problemen mit dieser. News sind ebenso spannend, sodass ich auch über Updates, Releases und Neuigkeiten aus der IT berichte. Letztendlich nutze ich Taste-of-IT als eigene Dokumentation und Anlaufstelle bei wiederkehrenden Themen. Ich hoffe ich kann dich ebenso informieren und bei Problemen eine schnelle Lösung anbieten. Wer meinen Aufwand unterstützen möchte, kann gerne eine Tasse oder Pod Kaffe per PayPal spenden – vielen Dank.