|
|
Subscribe / Log in / New account

Mageia alert MGASA-2024-0231 (thunderbird)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2024-0231: Updated thunderbird packages fix security vulnerabilities
Date:  Sat, 22 Jun 2024 19:33:23 +0200
Message-ID:  <20240622173323.CA3FE9F9ED@duvel.mageia.org>
Archive-link:  Article

MGASA-2024-0231 - Updated thunderbird packages fix security vulnerabilities Publication date: 22 Jun 2024 URL: https://advisories.mageia.org/MGASA-2024-0231.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-5702, CVE-2024-5688, CVE-2024-5690, CVE-2024-5691, CVE-2024-5693, CVE-2024-5696, CVE-2024-5700 Description: Use-after-free in networking. (CVE-2024-5702) Use-after-free in JavaScript object transplant. (CVE-2024-5688) External protocol handlers leaked by timing attack. (CVE-2024-5690) Sandboxed iframes were able to bypass sandbox restrictions to open a new window. (CVE-2024-5691) Cross-Origin Image leak via Offscreen Canvas. (CVE-2024-5693) Memory Corruption in Text Fragments. (CVE-2024-5696) Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. (CVE-2024-5700) References: - https://bugs.mageia.org/show_bug.cgi?id=33311 - https://www.thunderbird.net/en-US/thunderbird/115.12.0/re... - https://www.mozilla.org/en-US/security/advisories/mfsa202... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5702 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5688 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5690 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5691 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5693 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5696 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5700 SRPMS: - 9/core/thunderbird-115.12.0-1.mga9 - 9/core/thunderbird-l10n-115.12.0-1.mga9


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds