[RHSA-2023:1401] thunderbird security update
Severity
Important
Affected Packages
2
CVEs
5
Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 102.9.0.
Security Fix(es):
Mozilla: Incorrect code generation during JIT compilation (CVE-2023-25751)
Mozilla: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9 (CVE-2023-28176)
Mozilla: Potential out-of-bounds when accessing throttled streams (CVE-2023-25752)
Mozilla: Invalid downcast in Worklets (CVE-2023-28162)
Mozilla: URL being dragged from a removed cross-origin iframe into the same tab triggered navigation (CVE-2023-28164)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/redhat/thunderbird?arch=x86_64&distro=redhat-7.9 | < 102.9.0-1.el7_9 |
pkg:rpm/redhat/thunderbird?arch=ppc64le&distro=redhat-7.9 | < 102.9.0-1.el7_9 |
- ID
- RHSA-2023:1401
- Severity
- important
- URL
- https://access.redhat.com/errata/RHSA-2023:1401
- Published
-
2023-03-22T00:00:00
(18 months ago) - Modified
-
2023-03-22T00:00:00
(18 months ago) - Rights
- Copyright 2023 Red Hat, Inc.
- Other Advisories
-
- ALAS2-2023-1988
- ALPINE:CVE-2023-25751
- ALPINE:CVE-2023-25752
- ALPINE:CVE-2023-28162
- ALPINE:CVE-2023-28164
- ALPINE:CVE-2023-28176
- ALSA-2023:1336
- ALSA-2023:1337
- ALSA-2023:1403
- ALSA-2023:1407
- DSA-5374-1
- DSA-5375-1
- ELSA-2023-1333
- ELSA-2023-1336
- ELSA-2023-1337
- ELSA-2023-1401
- ELSA-2023-1403
- ELSA-2023-1407
- GLSA-202305-35
- GLSA-202305-36
- MFSA-2023-09
- MFSA-2023-10
- MFSA-2023-11
- RHSA-2023:1333
- RHSA-2023:1336
- RHSA-2023:1337
- RHSA-2023:1403
- RHSA-2023:1407
- RLSA-2023:1336
- RLSA-2023:1337
- RLSA-2023:1403
- RLSA-2023:1407
- SSA:2023-073-01
- SSA:2023-075-01
- SUSE-SU-2023:0728-1
- SUSE-SU-2023:0763-1
- SUSE-SU-2023:0835-1
- SUSE-SU-2023:1736-1
- USN-5954-1
- USN-5972-1
- USN-6120-1
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 2178458 | https://bugzilla.redhat.com/2178458 | |
Bugzilla | 2178460 | https://bugzilla.redhat.com/2178460 | |
Bugzilla | 2178466 | https://bugzilla.redhat.com/2178466 | |
Bugzilla | 2178470 | https://bugzilla.redhat.com/2178470 | |
Bugzilla | 2178472 | https://bugzilla.redhat.com/2178472 | |
RHSA | RHSA-2023:1401 | https://access.redhat.com/errata/RHSA-2023:1401 | |
CVE | CVE-2023-25751 | https://access.redhat.com/security/cve/CVE-2023-25751 | |
CVE | CVE-2023-25752 | https://access.redhat.com/security/cve/CVE-2023-25752 | |
CVE | CVE-2023-28162 | https://access.redhat.com/security/cve/CVE-2023-28162 | |
CVE | CVE-2023-28164 | https://access.redhat.com/security/cve/CVE-2023-28164 | |
CVE | CVE-2023-28176 | https://access.redhat.com/security/cve/CVE-2023-28176 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/thunderbird?arch=x86_64&distro=redhat-7.9 | redhat | thunderbird | < 102.9.0-1.el7_9 | redhat-7.9 | x86_64 | |
Affected | pkg:rpm/redhat/thunderbird?arch=ppc64le&distro=redhat-7.9 | redhat | thunderbird | < 102.9.0-1.el7_9 | redhat-7.9 | ppc64le |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |