[RHSA-2024:5392] thunderbird security update

Severity Important
Affected Packages 4
CVEs 10

Mozilla Thunderbird is a standalone mail and newsgroup client.

Security Fix(es):

  • EMBARGOED Thunderbird: 115.14/128.1 ()

  • mozilla: Fullscreen notification dialog can be obscured by document content (CVE-2024-7518)

  • mozilla: Out of bounds memory access in graphics shared memory handling (CVE-2024-7519)

  • mozilla: Type confusion in WebAssembly (CVE-2024-7520)

  • mozilla: Incomplete WebAssembly exception handing (CVE-2024-7521)

  • mozilla: Out of bounds read in editor component (CVE-2024-7522)

  • mozilla: Missing permission check when creating a StreamFilter (CVE-2024-7525)

  • mozilla: Uninitialized memory used by WebGL (CVE-2024-7526)

  • mozilla: Use-after-free in JavaScript garbage collection (CVE-2024-7527)

  • mozilla: Use-after-free in IndexedDB (CVE-2024-7528)

  • mozilla: Document content could partially obscure security prompts (CVE-2024-7529)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/thunderbird?arch=x86_64&distro=redhat-9.4 redhat thunderbird < 115.14.0-1.el9_4 redhat-9.4 x86_64
Affected pkg:rpm/redhat/thunderbird?arch=s390x&distro=redhat-9.4 redhat thunderbird < 115.14.0-1.el9_4 redhat-9.4 s390x
Affected pkg:rpm/redhat/thunderbird?arch=ppc64le&distro=redhat-9.4 redhat thunderbird < 115.14.0-1.el9_4 redhat-9.4 ppc64le
Affected pkg:rpm/redhat/thunderbird?arch=aarch64&distro=redhat-9.4 redhat thunderbird < 115.14.0-1.el9_4 redhat-9.4 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date