[ALSA-2024:3784] Moderate: thunderbird security update
Type:
security
Severity:
moderate
Release date:
2024-06-20
Description:
Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.11.0. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 thunderbird-115.11.0-1.el8_10.alma.1.aarch64.rpm 69af3610e34f6fdfc495ee412251142f4ea205be58455b1f3de2448a0e0a5535
ppc64le thunderbird-115.11.0-1.el8_10.alma.1.ppc64le.rpm 1fd9f6fafe258b1fa2490d15f2e0a739f8b905ae4381e549a29cbd250cc880ee
s390x thunderbird-115.11.0-1.el8_10.alma.1.s390x.rpm c33da09660129ff4e2fb09699867995794edf96388f208e82f28c7fabdb18bb6
x86_64 thunderbird-115.11.0-1.el8_10.alma.1.x86_64.rpm 46b2a935e481111f5d347e9f1cd611d40285a30931654b12fc7a63fbe5f1a0a8
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.