[ALSA-2024:4036] Important: thunderbird security update
Type:
security
Severity:
important
Release date:
2024-06-21
Description:
Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.12.1. Security Fix(es): * thunderbird: Use-after-free in networking (CVE-2024-5702) * thunderbird: Use-after-free in JavaScript object transplant (CVE-2024-5688) * thunderbird: External protocol handlers leaked by timing attack (CVE-2024-5690) * thunderbird: Sandboxed iframes were able to bypass sandbox restrictions to open a new window (CVE-2024-5691) * thunderbird: Cross-Origin Image leak via Offscreen Canvas (CVE-2024-5693) * thunderbird: Memory Corruption in Text Fragments (CVE-2024-5696) * thunderbird: Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12 (CVE-2024-5700) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 thunderbird-115.12.1-1.el8_10.alma.1.aarch64.rpm 089d7ce6c4e651f73a2c795e06b9f2a5c2686d0d2addcde0081de3f4ef10b221
ppc64le thunderbird-115.12.1-1.el8_10.alma.1.ppc64le.rpm 27391290d7391d7c620a97177c14901c7d264f9811fe3d9665de544b43b5f75e
s390x thunderbird-115.12.1-1.el8_10.alma.1.s390x.rpm ac07c53477237a122876a5c666ae7c1c15dcd866a7b6d045f74ca5204259edb8
x86_64 thunderbird-115.12.1-1.el8_10.alma.1.x86_64.rpm a753e85f54b24f7aad725ad5e757c5e155bdc0dbc97d8d49e72731a711f5fe9b
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.