[ALSA-2024:0964] Important: thunderbird security update
Type:
security
Severity:
important
Release date:
2024-02-28
Description:
Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.8.0. Security Fix(es): * Mozilla: Out-of-bounds memory read in networking channels (CVE-2024-1546) * Mozilla: Alert dialog could have been spoofed on another site (CVE-2024-1547) * Mozilla: Memory safety bugs fixed in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8 (CVE-2024-1553) * Mozilla: Fullscreen Notification could have been hidden by select element (CVE-2024-1548) * Mozilla: Custom cursor could obscure the permission dialog (CVE-2024-1549) * Mozilla: Mouse cursor re-positioned unexpectedly could have led to unintended permission grants (CVE-2024-1550) * Mozilla: Multipart HTTP Responses would accept the Set-Cookie header in response parts (CVE-2024-1551) * Mozilla: Incorrect code generation on 32-bit ARM devices (CVE-2024-1552) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 thunderbird-115.8.0-1.el8_9.alma.aarch64.rpm d3ab874ea50ce24936a84e0224b04416fa625de602aef6e4e2764024e7959321
ppc64le thunderbird-115.8.0-1.el8_9.alma.ppc64le.rpm 7bac6e3c4b8f7baa2fc54b320138a797bfc4cacef9e5437841ff918db8c18ed8
s390x thunderbird-115.8.0-1.el8_9.alma.s390x.rpm aca35657bcb9705478c28fa058fc8f9644184ef560f1044ffbdcd6d3d34a023f
x86_64 thunderbird-115.8.0-1.el8_9.alma.x86_64.rpm f074146e7eddd817729104549142b17072f4c4ac1856894f42e2586a4b74790e
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.