This update for MozillaThunderbird fixes the following issues:
Updated to Mozilla Thunderbird 102.2.2: - CVE-2022-3033: Fixed leaking of sensitive information when composing a response to an HTML email with a META refresh tag (bsc#1203007). - CVE-2022-3032: Fixed missing blocking of remote content specified in an HTML document that was nested inside an iframe's srcdoc attribute (bsc#1203007). - CVE-2022-3034: Fixed issue where iframe element in an HTML email could trigger a network request (bsc#1203007). - CVE-2022-36059: Fixed DoS in Matrix SDK bundled with Thunderbird service attack (bsc#1203007).
CVE-2022-38478: Fixed memory safety bugs (bsc#1202645).
CVE-2022-36319: Fixed mouse position spoofing with CSS transforms (bsc#1201758).
CVE-2022-2505: Fixed memory safety bugs (bsc#1201758).
CVE-2022-34479: Fixed vulnerability which could overlay the address bar with web content (bsc#1200793).
allow-scripts
bypass via retargeted javascript (bsc#1200793).