Updated thunderbird packages fix security vulnerabilities:
Uninitialized memory in a canvas object could have caused an incorrect
free() leading to memory corruption and a potentially exploitable crash
(CVE-2021-29980).
Instruction reordering during JIT optimization resulted in a sequence of
instructions that would cause an object to be incorrectly considered during
garbage collection. This led to memory corruption and a potentially
exploitable crash (CVE-2021-29984).
A use-after-free vulnerability in media channels could have led to memory
corruption and a potentially exploitable crash (CVE-2021-29985).
A suspected race condition when calling getaddrinfo while resolving DNS
names could have led to memory corruption and a potentially exploitable
crash (CVE-2021-29986).
Thunderbird incorrectly treated an inline list-item element as a block
element, resulting in an out of bounds read or memory corruption, and a
potentially exploitable crash (CVE-2021-29988).
Mozilla developers Christo...
- https://bugs.mageia.org/show_bug.cgi?id=29355
- https://www.thunderbird.net/en-US/thunderbird/78.13.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2021-35/
- https://www.cve.org/CVERecord?id=CVE-2021-29980
- https://www.cve.org/CVERecord?id=CVE-2021-29984
- https://www.cve.org/CVERecord?id=CVE-2021-29985
- https://www.cve.org/CVERecord?id=CVE-2021-29986
- https://www.cve.org/CVERecord?id=CVE-2021-29988
- https://www.cve.org/CVERecord?id=CVE-2021-29989
- 8/core/thunderbird-78.13.0-1.mga8
- 8/core/thunderbird-l10n-78.13.0-1.mga8
Get the latest Linux and open source security news straight to your inbox.