Thunderbird 156 schließt 75 Sicherheitslücken und baut OAuth-Funktionen aus

Thunderbird 156 Fixes 75 Security Flaws and Expands OAuth Features

Mozilla has released version 156 of its open-source email client Thunderbird. The update resolves a total of 75 security vulnerabilities while introducing practical improvements for account management, modern authentication methods, and OpenPGP encryption.

Urgent Security Update Patches 28 High-Severity Flaws

The unusually long list of fixed bugs is due to a policy change at Mozilla: internally discovered memory safety bugs now receive individual CVE identifiers, just as in Firefox 156, rather than being grouped under a single collective entry as before.

Of the 75 patched vulnerabilities, Mozilla rates 28 as “high” severity. The issues affect Web Codecs, the CanvasWebGL graphics engine, accessibility interfaces, and WebExtensions, among others. Several vulnerabilities could have allowed attackers to escape security sandboxes in the graphics subsystem or DOM Core & HTML, or to gain elevated privileges on the system. Users are advised to apply the update promptly.

More Flexibility with OAuth and OpenPGP

Beyond security patches, Thunderbird 156 brings functional upgrades for mail accounts. For IMAP and POP3 mailboxes, users can now configure custom OAuth settings including client IDs and client secrets. OAuth is a standardized authorization protocol that allows applications to access services without requiring direct password entry. For Yandex accounts, Thunderbird now supports authentication via an external web browser, and OAuth setup for Microsoft Exchange accounts is working properly again.

See also  Samsung Update Fixes 56 Security Vulnerabilities

When using OpenPGP for end-to-end encryption, key properties can now output debug data to the internal error console when needed. In addition, signatures created via external GnuPG will no longer fail if the primary key itself is not designated for signing.

New Enterprise Policies and File Handling Fixes

For administrators in enterprise environments, Mozilla has introduced three new policies:

  • DisableUpdateSettings: Prevents manual modifications to software update settings.
  • DisableDataCollectionSettings: Protects telemetry and data collection preferences from end-user changes.
  • DisableMessageForwardingFilters: Stops users from setting up automatic forwarding via message filters.

Numerous bug fixes address issues with attachments and mailbox folders. Previously, opening PDF files could result in blank tabs, or draft PDFs were mistakenly interpreted as HTML. Issues when deleting or detaching all attachments simultaneously, as well as rendering glitches for POP3 folder names exceeding 55 characters, have also been resolved.

Availability and How to Update

Thunderbird 156 is available now. The update is typically distributed automatically via the built-in update mechanism, but it can also be triggered manually through the Help menu under “About Thunderbird”. For enterprise deployments, extended support releases (Thunderbird 153.3.0 ESR and Thunderbird 140.16 ESR) are available in parallel.

Quellen: Computerbase.de/news

Leave a Comment

Your email address will not be published. Required fields are marked *

Mastodon
Scroll to Top