Slackware Linux update for mozilla-thunderbird (SSA



Risk Medium
Patch available YES
Number of vulnerabilities 4
CVE-ID CVE-2022-39236
CVE-2022-39249
CVE-2022-39250
CVE-2022-39251
CWE-ID CWE-20
CWE-345
Exploitation vector Network
Public exploit N/A
Vulnerable software
Slackware Linux
Operating systems & Components / Operating system

mozilla-thunderbird
Operating systems & Components / Operating system package or component

Vendor Slackware

Security Bulletin

This security bulletin contains information about 4 vulnerabilities.

1) Input validation error

EUVDB-ID: #VU67744

Risk: Medium

CVSSv4.0: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2022-39236

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when processing beacon events. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.

Mitigation

Update the affected package mozilla-thunderbird (SSA.

Vulnerable software versions

Slackware Linux: 15.0

mozilla-thunderbird: before 102.3.1

CPE2.3 External links

https://www.slackware.com/security/viewer.php?l=slackware-security&y=2022&m=slackware-security.383715


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Insufficient verification of data authenticity

EUVDB-ID: #VU67742

Risk: Low

CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-39249

CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to a very permissive key forwarding strategy. A remote attacker cooperating with a malicious home server can construct messages appearing to have come from another person.

Mitigation

Update the affected package mozilla-thunderbird (SSA.

Vulnerable software versions

Slackware Linux: 15.0

mozilla-thunderbird: before 102.3.1

CPE2.3 External links

https://www.slackware.com/security/viewer.php?l=slackware-security&y=2022&m=slackware-security.383715


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Insufficient verification of data authenticity

EUVDB-ID: #VU67745

Risk: Medium

CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2022-39250

CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass SAS verification.

The vulnerability exists due to checking and signing user identities and devices in two separate steps, and inadequately fixing the keys to be signed between these steps. A remote attacker cooperating with a malicious home server can interfere with the verification flow between two users, injecting its own cross-signing user identity in place of one of the users’ identities, leading to the other device trusting/verifying the user identity under the control of the home server instead of the intended one.

Mitigation

Update the affected package mozilla-thunderbird (SSA.

Vulnerable software versions

Slackware Linux: 15.0

mozilla-thunderbird: before 102.3.1

CPE2.3 External links

https://www.slackware.com/security/viewer.php?l=slackware-security&y=2022&m=slackware-security.383715


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Insufficient verification of data authenticity

EUVDB-ID: #VU67743

Risk: Low

CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-39251

CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity

Exploit availability: No

Description

he vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. A remote attacker cooperating with a malicious home server can construct messages appearing to have come from another person without any indication such as a grey shield.

Mitigation

Update the affected package mozilla-thunderbird (SSA.

Vulnerable software versions

Slackware Linux: 15.0

mozilla-thunderbird: before 102.3.1

CPE2.3 External links

https://www.slackware.com/security/viewer.php?l=slackware-security&y=2022&m=slackware-security.383715


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###