{"id":"MGASA-2022-0221","summary":"Updated thunderbird packages fix security vulnerability","details":"When displaying the sender of an email, and the sender name contained the\nBraille Pattern Blank space character multiple times, Thunderbird would have\ndisplayed all the spaces. This could have been used by an attacker to send an\nemail message with the attacker's digital signature, that was shown with an\narbitrary sender email address chosen by the attacker. If the sender name\nstarted with a false email address, followed by many Braille space characters,\nthe attacker's email address was not visible. Because Thunderbird compared the\ninvisible sender address with the signature's email address, if the signing\nkey or certificate was accepted by Thunderbird, the email was shown as having\na valid digital signature (CVE-2022-1834).\n\nA malicious website could have learned the size of a cross-origin resource\nthat supported Range requests (CVE-2022-31736).\n\nA malicious webpage could have caused an out-of-bounds write in WebGL, leading\nto memory corruption and a potentially exploitable crash (CVE-2022-31737).\n\nWhen exiting fullscreen mode, an iframe could have confused the browser about\nthe current state of fullscreen, resulting in potential user confusion or\nspoofing attacks (CVE-2022-31738).\n\nOn arm64, WASM code could have resulted in incorrect assembly generation\nleading to a register allocation problem, and a potentially exploitable crash\n(CVE-2022-31740).\n\nA crafted CMS message could have been processed incorrectly, leading to an\ninvalid memory read, and potentially further memory corruption\n(CVE-2022-31741).\n\nAn attacker could have exploited a timing attack by sending a large number of\nallowCredential entries and detecting the difference between invalid key\nhandles and cross-origin key handles. This could have led to cross-origin\naccount linking in violation of WebAuthn goals (CVE-2022-31742).\n\nMozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla\nFuzzing Team reported memory safety bugs present in Thunderbird 91.9. Some of\nthese bugs showed evidence of memory corruption and we presume that with\nenough effort some of these could have been exploited to run arbitrary code\n","modified":"2026-04-16T04:43:25.567239734Z","published":"2022-06-04T20:25:39Z","upstream":["CVE-2022-1834","CVE-2022-31736","CVE-2022-31737","CVE-2022-31738","CVE-2022-31740","CVE-2022-31741","CVE-2022-31742","CVE-2022-31747"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2022-0221.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=30499"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2022-22/"},{"type":"WEB","url":"https://www.thunderbird.net/en-US/thunderbird/91.10.0/releasenotes/"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2022:4892"}],"affected":[{"package":{"name":"thunderbird","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"91.10.0-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0221.json"}},{"package":{"name":"thunderbird-l10n","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"91.10.0-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0221.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}