[ALSA-2024:4002] Important: thunderbird security update
Type:
security
Severity:
important
Release date:
2024-06-20
Description:
Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.12.1. Security Fix(es): * thunderbird: Use-after-free in networking (CVE-2024-5702) * thunderbird: Use-after-free in JavaScript object transplant (CVE-2024-5688) * thunderbird: External protocol handlers leaked by timing attack (CVE-2024-5690) * thunderbird: Sandboxed iframes were able to bypass sandbox restrictions to open a new window (CVE-2024-5691) * thunderbird: Cross-Origin Image leak via Offscreen Canvas (CVE-2024-5693) * thunderbird: Memory Corruption in Text Fragments (CVE-2024-5696) * thunderbird: Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12 (CVE-2024-5700) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 thunderbird-115.12.1-1.el9_4.alma.1.aarch64.rpm 7500537fcf08edb65d7050e69f00f5ccfb86294a169f6ed1860377f8994443eb
ppc64le thunderbird-115.12.1-1.el9_4.alma.1.ppc64le.rpm 52b11ec8b36a5fc8ca9c6dbd1e4769c8db5c90badf8850005eb69a3b0fcdf74d
s390x thunderbird-115.12.1-1.el9_4.alma.1.s390x.rpm 1d7c67a31884ec62ee83a84453e0dce5a353c25d11d0e083623600f92a90c142
x86_64 thunderbird-115.12.1-1.el9_4.alma.1.x86_64.rpm 3b323666ec94e5a347f3ce8322c134a499a9cac1d6c95ecb709dc19d372b2614
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.