-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5463-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 30, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : thunderbird CVE ID : CVE-2023-3417 A security issue was discovered in Thunderbird, which could result in spoofing of filenames of email attachments. For the oldstable distribution (bullseye), this problem has been fixed in version 1:102.13.1-1~deb11u1. For the stable distribution (bookworm), this problem has been fixed in version 1:102.13.1-1~deb12u1. We recommend that you upgrade your thunderbird packages. For the detailed security status of thunderbird please refer to its security tracker page at: https://security-tracker.debian.org/tracker/thunderbird Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmTGuwwACgkQEMKTtsN8 TjYYQg/9G3hyhs/ad+Risih2ABSgcZna8glNT9zwOY+xWuHDpbRiX1NiNE5rqjgU dhkZOFYbRkON8RnUsM3vodYDA0uBZmh2pXBDg8pmE/b0FGYho+V6/uh6a8bc1HlG 4S2E2DMwesof6Fg2iQtkdd2tkPByzKvj/FEs6ZWKa20NIxlVxfb5aaqX/l/WVnwX Izaz6J7hQYWRIjF+TpTgtrX/wl3zM7ZDas1CEWZWWYQ3QSZrA1aTQuOUqq5t7JPb rY1/OAiUrojvCATgaGb0adwlB2Ad6zq4wrJpc99mKpzYKfe6L8VcOYf5jDEHxopE 856I/h9UImpBcvHrwbYL/kBetCm0ZFUqCnJlVUBmEPID0DnsYUUbC6v48erfuS0/ Fo41knXeowMaCwOeUk6M7AWr2FQmP6S82eNnNs0wbWLcsQ/OV3bchbqZ6hK2bEXr Iv3Vi5ZecY6RcJiOfBgvmP9nGsUGAKJC5sKtbBpzwU0NnDskmnubcLh3ak/1S0oB D4nYCYzwQTnqyyaAV1AnRSHfZPk5xpMz7RUNk9zBcfu5kUgbFZ+rCmyCXejhXA5O O4Pggz1SCe/AWrGuJXYVIO2GgL4LroukbDjt3s48TGKH9IuruNF9msjRlWpPTj80 khVYn9D68QxIA3Mt36qoTLmm2gFJcu8Cde6XYFWnL4FaKPASqUY= =tNnR -----END PGP SIGNATURE-----