[RHSA-2020:4163] thunderbird security update
Severity
Important
Affected Packages
2
CVEs
4
Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 78.3.1.
Security Fix(es):
Mozilla: Memory safety bugs fixed in Firefox 81 and Firefox ESR 78.3 (CVE-2020-15673)
Mozilla: XSS when pasting attacker-controlled data into a contenteditable element (CVE-2020-15676)
Mozilla: Download origin spoofing via redirect (CVE-2020-15677)
Mozilla: When recursing through layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free scenario (CVE-2020-15678)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/redhat/thunderbird?arch=x86_64&distro=redhat-7.9 | < 78.3.1-1.el7_9 |
pkg:rpm/redhat/thunderbird?arch=ppc64le&distro=redhat-7.9 | < 78.3.1-1.el7_9 |
- ID
- RHSA-2020:4163
- Severity
- important
- URL
- https://access.redhat.com/errata/RHSA-2020:4163
- Published
-
2020-10-01T00:00:00
(4 years ago) - Modified
-
2020-10-01T00:00:00
(4 years ago) - Rights
- Copyright 2020 Red Hat, Inc.
- Other Advisories
-
- ALAS2-2020-1572
- ALPINE:CVE-2020-15673
- ALPINE:CVE-2020-15676
- ALPINE:CVE-2020-15677
- ALPINE:CVE-2020-15678
- ASA-202009-10
- DSA-4768-1
- DSA-4770-1
- ELSA-2020-3832
- ELSA-2020-3835
- ELSA-2020-4080
- ELSA-2020-4155
- ELSA-2020-4158
- ELSA-2020-4163
- GLSA-202010-02
- MFSA-2020-42
- MFSA-2020-43
- MFSA-2020-44
- openSUSE-SU-2020:1555-1
- openSUSE-SU-2020:1574-1
- openSUSE-SU-2020:1780-1
- openSUSE-SU-2020:1785-1
- RHSA-2020:3832
- RHSA-2020:3835
- RHSA-2020:4080
- RHSA-2020:4155
- RHSA-2020:4158
- SUSE-SU-2020:2747-1
- SUSE-SU-2020:2749-1
- SUSE-SU-2020:2759-1
- SUSE-SU-2020:3091-1
- USN-4546-1
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 1881664 | https://bugzilla.redhat.com/1881664 | |
Bugzilla | 1881665 | https://bugzilla.redhat.com/1881665 | |
Bugzilla | 1881666 | https://bugzilla.redhat.com/1881666 | |
Bugzilla | 1881667 | https://bugzilla.redhat.com/1881667 | |
RHSA | RHSA-2020:4163 | https://access.redhat.com/errata/RHSA-2020:4163 | |
CVE | CVE-2020-15673 | https://access.redhat.com/security/cve/CVE-2020-15673 | |
CVE | CVE-2020-15676 | https://access.redhat.com/security/cve/CVE-2020-15676 | |
CVE | CVE-2020-15677 | https://access.redhat.com/security/cve/CVE-2020-15677 | |
CVE | CVE-2020-15678 | https://access.redhat.com/security/cve/CVE-2020-15678 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/thunderbird?arch=x86_64&distro=redhat-7.9 | redhat | thunderbird | < 78.3.1-1.el7_9 | redhat-7.9 | x86_64 | |
Affected | pkg:rpm/redhat/thunderbird?arch=ppc64le&distro=redhat-7.9 | redhat | thunderbird | < 78.3.1-1.el7_9 | redhat-7.9 | ppc64le |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |