[RLSA-2024:1494] thunderbird security update
An update is available for thunderbird. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list
Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 115.9.0.
Security Fix(es):
nss: timing attack against RSA decryption (CVE-2023-5388)
Mozilla: Crash in NSS TLS method (CVE-2024-0743)
Mozilla: Leaking of encrypted email subjects to other conversations (CVE-2024-1936)
Mozilla: JIT code failed to save return registers on Armv7-A (CVE-2024-2607)
Mozilla: Integer overflow could have led to out of bounds write
(CVE-2024-2608)Mozilla: Improper handling of html and body tags enabled CSP nonce leakage
(CVE-2024-2610)Mozilla: Clickjacking vulnerability could have led to a user accidentally
granting permissions (CVE-2024-2611)Mozilla: Self referencing object could have potentially led to a
use-after-free (CVE-2024-2612)Mozilla: Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and
Thunderbird 115.9 (CVE-2024-2614)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/rockylinux/thunderbird?arch=x86_64&distro=rockylinux-8.9 | < 115.9.0-1.el8_9 |
pkg:rpm/rockylinux/thunderbird?arch=aarch64&distro=rockylinux-8.9 | < 115.9.0-1.el8_9 |
- ID
- RLSA-2024:1494
- Severity
- moderate
- URL
- https://errata.rockylinux.org/RLSA-2024:1494
- Published
-
2024-03-27T04:34:32
(5 months ago) - Modified
-
2024-03-27T04:36:48
(5 months ago) - Rights
- Copyright 2024 Rocky Enterprise Software Foundation
- Other Advisories
-
- ALAS-2024-1907
- ALAS2-2024-2419
- ALAS2-2024-2497
- ALAS2-2024-2505
- ALPINE:CVE-2023-5388
- ALPINE:CVE-2024-0743
- ALPINE:CVE-2024-2607
- ALPINE:CVE-2024-2608
- ALPINE:CVE-2024-2610
- ALPINE:CVE-2024-2611
- ALPINE:CVE-2024-2612
- ALPINE:CVE-2024-2614
- ALSA-2024:0105
- ALSA-2024:0108
- ALSA-2024:1484
- ALSA-2024:1485
- ALSA-2024:1493
- ALSA-2024:1494
- DSA-5643-1
- DSA-5644-1
- ELSA-2024-0105
- ELSA-2024-0108
- ELSA-2024-1484
- ELSA-2024-1485
- ELSA-2024-1486
- ELSA-2024-1493
- ELSA-2024-1494
- ELSA-2024-1498
- GLSA-202402-26
- GLSA-202405-32
- MFSA-2024-01
- MFSA-2024-11
- MFSA-2024-12
- MFSA-2024-13
- MFSA-2024-14
- RHSA-2024:0105
- RHSA-2024:0108
- RHSA-2024:1484
- RHSA-2024:1485
- RHSA-2024:1486
- RHSA-2024:1493
- RHSA-2024:1494
- RHSA-2024:1498
- RLSA-2024:0105
- RLSA-2024:1484
- SSA:2024-065-01
- SSA:2024-079-02
- SSA:2024-079-03
- SUSE-SU-2024:0578-1
- SUSE-SU-2024:0579-1
- SUSE-SU-2024:0597-1
- SUSE-SU-2024:0893-1
- SUSE-SU-2024:0971-1
- SUSE-SU-2024:1002-1
- SUSE-SU-2024:1147-1
- SUSE-SU-2024:2600-1
- USN-6610-1
- USN-6669-1
- USN-6703-1
- USN-6717-1
- USN-6727-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/rockylinux/thunderbird?arch=x86_64&distro=rockylinux-8.9 | rockylinux | thunderbird | < 115.9.0-1.el8_9 | rockylinux-8.9 | x86_64 | |
Affected | pkg:rpm/rockylinux/thunderbird?arch=aarch64&distro=rockylinux-8.9 | rockylinux | thunderbird | < 115.9.0-1.el8_9 | rockylinux-8.9 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |