Security update for MozillaThunderbird
This update for MozillaThunderbird fixes the following issues: - Mozilla Thunderbird 78.10.2 - CVE-2021-29957: Fixed partial protection of inline OpenPGP message not indicated (bsc#1186198). - CVE-2021-29956: Fixed Thunderbird stored OpenPGP secret keys without master password protection (bsc#1186199). - CVE-2021-29951: Fixed Thunderbird Maintenance Service could have been started or stopped by domain users (bsc#1185633). - CVE-2021-29950: Fixed logic issue potentially leaves key material unlocked (bsc#1185086).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for MozillaThunderbird fixes the following issues: - Mozilla Thunderbird 78.10.2 - CVE-2021-29957: Fixed partial protection of inline OpenPGP message not indicated (bsc#1186198). - CVE-2021-29956: Fixed Thunderbird stored OpenPGP secret keys without master password protection (bsc#1186199). - CVE-2021-29951: Fixed Thunderbird Maintenance Service could have been started or stopped by domain users (bsc#1185633). - CVE-2021-29950: Fixed logic issue potentially leaves key material unlocked (bsc#1185086).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1185086
- https://bugzilla.suse.com/1185633
- https://bugzilla.suse.com/1186198
- https://bugzilla.suse.com/1186199
- https://www.suse.com/security/cve/CVE-2021-29950
- https://www.suse.com/security/cve/CVE-2021-29951
- https://www.suse.com/security/cve/CVE-2021-29956
- https://www.suse.com/security/cve/CVE-2021-29957
- https://www.suse.com/support/update/announcement/2021/suse-su-20211854-1/