FlawAtlas
Search the atlas
SUSE-SU-2023:4302-1 Not scored

Security update for MozillaThunderbird

This update for MozillaThunderbird fixes the following issues: - Updated to version 115.4.1: - CVE-2023-5721: Fixed a potential clickjack via queued up rendering. - CVE-2023-5732: Fixed an address bar spoofing via bidirectional characters - CVE-2023-5724: Fixed a crash due to a large WebGL draw. - CVE-2023-5725: Fixed an issue where WebExtensions could open arbitrary URLs. - CVE-2023-5726: Fixed an issue where fullscreen notifications would be obscured by file the open dialog on macOS. - CVE-2023-5727: Fixed a download protection bypass on on Windows. - CVE-2023-5728: Fixed a crash caused by improper object tracking during GC in the JavaScript engine. - CVE-2023-5730: Fixed multiple memory safety issues.

Exploit probability Not scored
Published October 31, 2023
Required by Not available
Last source change May 2, 2025

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP4 MozillaThunderbird
SUSE:Linux Enterprise Module for Package Hub 15 SP5 MozillaThunderbird
SUSE:Linux Enterprise Workstation Extension 15 SP4 MozillaThunderbird
SUSE:Linux Enterprise Workstation Extension 15 SP5 MozillaThunderbird
openSUSE:Leap 15.4 MozillaThunderbird
openSUSE:Leap 15.5 MozillaThunderbird

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:4302-1

This update for MozillaThunderbird fixes the following issues: - Updated to version 115.4.1: - CVE-2023-5721: Fixed a potential clickjack via queued up rendering. - CVE-2023-5732: Fixed an address bar spoofing via bidirectional characters - CVE-2023-5724: Fixed a crash due to a large WebGL draw. - CVE-2023-5725: Fixed an issue where WebExtensions could open arbitrary URLs. - CVE-2023-5726: Fixed an issue where fullscreen notifications would be obscured by file the open dialog on macOS. - CVE-2023-5727: Fixed a download protection bypass on on Windows. - CVE-2023-5728: Fixed a crash caused by improper object tracking during GC in the JavaScript engine. - CVE-2023-5730: Fixed multiple memory safety issues.

View original source

05 / REFERENCES

Further evidence