Fix 7 "high" level vulnerabilities and release updates from Mozilla email client Thunderbird 102.6.0
CTOnews.com December 15 news, Mozilla recently released the Thunderbird 102.6.0 version update. This update fixes seven security vulnerabilities, all of which are marked as "High", second only to the "critical" level.
Seven vulnerabilities fixed by Thunderbird 102.6.0 include:
CVE-2022-46878: fixed a memory security vulnerability in Thunderbird 102.6
CVE-2022-46881: fixed memory corruption in WebGL
CVE-2022-46880: fixed Use-after-free problem in WebGL
CVE-2022-46872: fixed a vulnerability to arbitrarily read files from corrupted content processes
CVE-2022-46882: fixed Use-after-free vulnerability in WebGL
Cve-2022-46875: .atloc and .ftploc files on Mac OS bypass download protection
CVE-2022-46874: drag-and-drop filenames may be truncated to malicious extensions
In the update log, Thunderbird 102.6.0 also fixed seven non-security vulnerabilities that were reported or discovered by users in previous versions. One fixes the problem of displaying cookies, and the other fixes the pause RSS feed option in the e-mail client RSS reader.
CTOnews.com learned that Mozilla Thunderbird, informally known as Thunderbird in Chinese, is a free and open source cross-platform email client, news reader, aggregator and instant messaging software developed by the Mozilla Foundation. This software is installed on Ubuntu by default.