[ALAS2-2023-2294] Amazon Linux 2 2017.12 - ALAS2-2023-2294: medium priority package update for thunderbird
Severity
Medium
Affected Packages
4
CVEs
1
Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2023-44488:
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
Package | Affected Version |
---|---|
pkg:rpm/amazonlinux/thunderbird?arch=x86_64&distro=amazonlinux-2 | < 102.15.1-1.amzn2.0.2 |
pkg:rpm/amazonlinux/thunderbird?arch=aarch64&distro=amazonlinux-2 | < 102.15.1-1.amzn2.0.2 |
pkg:rpm/amazonlinux/thunderbird-debuginfo?arch=x86_64&distro=amazonlinux-2 | < 102.15.1-1.amzn2.0.2 |
pkg:rpm/amazonlinux/thunderbird-debuginfo?arch=aarch64&distro=amazonlinux-2 | < 102.15.1-1.amzn2.0.2 |
- ID
- ALAS2-2023-2294
- Severity
- medium
- URL
- https://alas.aws.amazon.com/AL2/ALAS-2023-2294.html
- Published
-
2023-10-12T15:09:00
(11 months ago) - Modified
-
2023-10-19T23:40:00
(11 months ago) - Rights
- Amazon Linux Security Team
- Other Advisories
-
- ALSA-2023:5537
- ALSA-2023:5539
- ALSA-2023:6187
- ALSA-2023:6188
- ALSA-2023:6191
- ALSA-2023:6194
- DSA-5518-1
- ELSA-2023-5537
- ELSA-2023-5539
- ELSA-2023-6162
- ELSA-2023-6187
- ELSA-2023-6188
- ELSA-2023-6191
- ELSA-2023-6193
- ELSA-2023-6194
- FEDORA-2023-f696934fbf
- GLSA-202310-04
- RHSA-2023:5537
- RHSA-2023:5539
- RHSA-2023:6162
- RHSA-2023:6187
- RHSA-2023:6188
- RHSA-2023:6191
- RHSA-2023:6194
- RLSA-2023:6188
- SUSE-SU-2024:2409-1
- USN-6403-1
- USN-6403-2
- USN-6403-3
Source | # ID | Name | URL |
---|---|---|---|
CVE | CVE-2023-44488 | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44488 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/amazonlinux/thunderbird?arch=x86_64&distro=amazonlinux-2 | amazonlinux | thunderbird | < 102.15.1-1.amzn2.0.2 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/thunderbird?arch=aarch64&distro=amazonlinux-2 | amazonlinux | thunderbird | < 102.15.1-1.amzn2.0.2 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/thunderbird-debuginfo?arch=x86_64&distro=amazonlinux-2 | amazonlinux | thunderbird-debuginfo | < 102.15.1-1.amzn2.0.2 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/thunderbird-debuginfo?arch=aarch64&distro=amazonlinux-2 | amazonlinux | thunderbird-debuginfo | < 102.15.1-1.amzn2.0.2 | amazonlinux-2 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |