Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia 7, 8: 2021-0164 Moderate: Thunderbird Out-Of-Bound Read

mageia
Calendar Grey March 30, 2021
Dist Mageia Esm H88
Recent updates for Thunderbird available on Mageia tackle various security concerns to improve user protection. More information below.
Texture upload into an unbound backing buffer resulted in an out-of-bound read

Summary

Texture upload into an unbound backing buffer resulted in an out-of-bound read. (CVE-2021-23981)
Angle graphics library out of date. (MOZ-2021-0002)
Internal network hosts could have been probed by a malicious webpage. (CVE-2021-23982)
Malicious extensions could have spoofed popup information. (CVE-2021-23984)
Memory safety bugs fixed in Thunderbird 78.9. (CVE-2021-23987)

References

- https://bugs.mageia.org/show_bug.cgi?id=28642

- https://www.thunderbird.net/en-US/thunderbird/78.9.0/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2021-12/

- https://www.cve.org/CVERecord?id=CVE-2021-23981

- https://www.cve.org/CVERecord?id=CVE-2021-23982

- https://www.cve.org/CVERecord?id=CVE-2021-23984

- https://www.cve.org/CVERecord?id=CVE-2021-23987

Resolution

SRPMS

- 8/core/thunderbird-l10n-78.9.0-1.mga8

- 8/core/thunderbird-78.9.0-1.mga8

- 7/core/thunderbird-l10n-78.9.0-1.mga7

- 7/core/thunderbird-78.9.0-1.mga7

Publication date: 30 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0164.html
Type: security
CVE: CVE-2021-23981, CVE-2021-23982, CVE-2021-23984, CVE-2021-23987

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here