-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2023.1632
                        thunderbird security update
                               20 March 2023

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           thunderbird
Publisher:         Debian
Operating System:  Debian GNU/Linux
Resolution:        Patch/Upgrade
CVE Names:         CVE-2023-28176 CVE-2023-28164 CVE-2023-28162
                   CVE-2023-25752 CVE-2023-25751 

Original Bulletin: 
   http://www.debian.org/security/2023/dsa-5375

Comment: CVSS (Max):  7.5 CVE-2023-28176 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVSS Source: Red Hat
Calculator:  https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

- --------------------------BEGIN INCLUDED TEXT--------------------

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-5375-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
March 17, 2023                        https://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : thunderbird
CVE ID         : CVE-2023-25751 CVE-2023-25752 CVE-2023-28162 CVE-2023-28164 
                 CVE-2023-28176

Multiple security issues were discovered in Thunderbird, which could
result in denial of service, the execution of arbitrary code or
spoofing.

For the stable distribution (bullseye), these problems have been fixed in
version 1:102.9.0-1~deb11u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmQUMlYACgkQEMKTtsN8
TjbFuRAAu5eB/iJm7+hwpVvqGITNNMkHe7OvnnNRnJ85Ot2Om74+8Q8vorj8Veye
ROk2N8KHBiehQha1sNSq6SAZ4qaSXJFkQOlm6vH/MSlsf9wGQ5apmpmQAPZ9V0F1
KgcOqtdq+lwd9DTXlcXPARumDLdkd8NrashhIvqJGaDFBqWoJOqp7NJHqvNPQzbL
inKqn30cDYcSUzVCdWCOxnrVGLrwTwLWvNCyslBZmTmNg1nKViqisLp59tscrchV
Lw0cJnVBQBA+BH3PdF6hzL2d9ilzT4cYgoVnqbAoyLCuKQMRlRpV6vk4Qguv5lMW
o7Gjc9bIoWoRMDNyt4PhmEcjJQLUpv+7lR3qv51b2J9Ga4pCsUJZ/my2ZFC/xysn
Nsm8KRXNIk8ZQvdkYL6RHuphdXmHAzjhyLy9/PLvAc1rVtOz9Niu/d/a0ipkyH+u
zEH/zcinFJFoGOOit2vx6lfrg+41E+EJKXw34oFq+TBlLc7a0kQn+OJEAoC0tMsU
zPvxdOfbVy9KCkXPSbCrqf6xpNKTJeKBcRUK6GSyvUL6T3AWXb26lNbRL6uo10j0
gl1E7clYqlv4qK+zVz1h9EtYeNdJcUnJxMypFhpHD8+BO2VvH4EZ4gpzZcAWDWk/
xBgLrxQ0uiJI43LKCrgMXAbotd0w2McPKOAdLH0Yq+lUJZ6tVIs=
=Mv0t
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: https://auscert.org.au/gpg-key/

iQIVAwUBZBe0qMkNZI30y1K9AQgJMA/+N6Ppa+s26X2DFlqQ0fuRyiKbD+ro1Awt
oQJRc2I7ocogHb8EOjh/f0hyxBf8CGN+W6Bim5wBPKW6ZMHBDt///YVr19TApoSE
1WW80Nyekq77JobzkWrzuI888DQhAtUqiJ5jxELZ7ezVlOfZIki/HIo0tNI6qmEX
mD96DoSrAt8rG3WScDEGBZpga7S3Ype5mjkz+3WNVtNOMZkolRxb0l8ue+CkBhYA
4X9qJ4wD44S//O3u0VnG60YlNsQWyUfibgMTfT37T/crmR/YLD/Pt0CTs/djd3Q3
CyORsKnJiQ3TnLm/j3F8foZxP/Gg+2XJRbX995Eh9pxv5XOma2PZ9pHOTFeOHFXb
hNHJ7MBlmkwecxHDWFifDBJvwpb3CHSOi1gwoW+JYuhAV4RB7YkztCBtEStcBYqO
Q0uoS57HMxAL9mmFjj+XSpgO2Vfs0h5L3LWOFr9yGZ4chsqaRVXEY+A+A6Kgfngz
BlhGvxQVQJY0kFwMdmFe6OtNyK1Hty8xUVgIlXPgctt3nFi7cnKIPnl5CEfkwU5B
KSM4wbAtp8/Boo8v5skvFoPd1oMzzGkyTqutrAu8YCZfYYxF1GiNF9k1GD/w+MIg
cDSyFzOZt9UimTt9llcYdVgrfmhD8InZCIhyZkPMr3+XhTdMvJHRy5dIhZWzor5H
upkHuu8de2E=
=qeD7
-----END PGP SIGNATURE-----