Synopsis
The remote SUSE host is missing one or more security updates.
Description
The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 / openSUSE 15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2023:0599-1 advisory.
  - If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to     process and display the message, which could cause Thunderbird's user interface to lock up and no longer     respond to the user's actions. An attacker could send a crafted message with this structure to attempt a     DoS attack. This vulnerability affects Thunderbird < 102.8. (CVE-2023-0616)
  - An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory     writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110,     Thunderbird < 102.8, and Firefox ESR < 102.8. (CVE-2023-0767)
  - The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child     iframe's unredacted URI when interaction with that iframe triggers a redirect. This vulnerability affects     Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8. (CVE-2023-25728)
  - Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code>     resulting in extensions being able to open them without user interaction via     <code>ExpandedPrincipals</code>. This could lead to further malicious actions such as downloading files or     interacting with software already installed on the system. This vulnerability affects Firefox < 110,     Thunderbird < 102.8, and Firefox ESR < 102.8. (CVE-2023-25729)
  - A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force     the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks.
    This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8. (CVE-2023-25730)
  - When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being     encoded was not correctly calculated potentially leading to an out of bounds memory write. This     vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8. (CVE-2023-25732)
  - After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply     a remote path that would lead to unexpected network requests from the operating system. This also had the     potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox on Windows. Other     operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and     Firefox ESR < 102.8. (CVE-2023-25734)
  - Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to     be stored in the main compartment resulting in a use-after-free after unwrapping the proxy. This     vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8. (CVE-2023-25735)
  - An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined     behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
    (CVE-2023-25737)
  - Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and     could have resulted in invalid values which in turn would cause the browser to attempt out of bounds     access to related variables.<br>*This bug only affects Firefox on Windows. Other operating systems are     unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
    (CVE-2023-25738)
  - Module load requests that failed were not being checked as to whether or not they were cancelled causing a     use-after-free in <code>ScriptLoadContext</code>. This vulnerability affects Firefox < 110, Thunderbird <     102.8, and Firefox ESR < 102.8. (CVE-2023-25739)
  - When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab     to crash. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
    (CVE-2023-25742)
  - Mozilla developers Philipp and Gabriele Svelto reported memory safety bugs present in Firefox ESR 102.7.
    Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of     these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 102.8 and     Firefox ESR < 102.8. (CVE-2023-25746)
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected MozillaThunderbird, MozillaThunderbird-translations-common and / or MozillaThunderbird-translations- other packages.
Plugin Details
File Name: suse_SU-2023-0599-1.nasl
Agent: unix
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C
Vulnerability Information
CPE: p-cpe:/a:novell:suse_linux:mozillathunderbird, p-cpe:/a:novell:suse_linux:mozillathunderbird-translations-other, cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:mozillathunderbird-translations-common
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: Exploits are available
Patch Publication Date: 3/2/2023
Vulnerability Publication Date: 2/14/2023
Reference Information
CVE: CVE-2023-0616, CVE-2023-0767, CVE-2023-25728, CVE-2023-25729, CVE-2023-25730, CVE-2023-25732, CVE-2023-25734, CVE-2023-25735, CVE-2023-25737, CVE-2023-25738, CVE-2023-25739, CVE-2023-25742, CVE-2023-25746
SuSE: SUSE-SU-2023:0599-1