Description:
Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 91.9.0.
Security Fix(es):
* Mozilla: Bypassing permission prompt in nested browsing contexts (CVE-2022-29909)
* Mozilla: iframe Sandbox bypass (CVE-2022-29911)
* Mozilla: Fullscreen notification bypass using popups (CVE-2022-29914)
* Mozilla: Leaking browser history with CSS variables (CVE-2022-29916)
* Mozilla: Memory safety bugs fixed in Firefox 100 and Firefox ESR 91.9 (CVE-2022-29917)
* Mozilla: Reader mode bypassed SameSite cookies (CVE-2022-29912)
* Mozilla: Speech Synthesis feature not properly disabled (CVE-2022-29913)
* Mozilla: Incorrect security status shown after viewing an attached email (CVE-2022-1520)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture |
Package |
Checksum |
aarch64 |
thunderbird-91.9.0-3.el8_5.alma.aarch64.rpm |
0beb99a9ecb26da80986c4d102311d2266f7624a5013311ca3ee754d90225d53 |
ppc64le |
thunderbird-91.9.0-3.el8_5.alma.ppc64le.rpm |
ebf72ec1441a0ae6a454cf617c398dc1677e46f610583de7e3bd3bcbf52e8495 |
x86_64 |
thunderbird-91.9.0-3.el8_5.alma.x86_64.rpm |
e237ec03335f626f6a8c5e88b1131b9747fe9944b62ed2daa2b1be622bb1aee9 |