Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 8: 2021-0584 Moderate: Thunderbird OpenPGP Buffer Overflow

mageia
Calendar Grey December 23, 2021
Dist Mageia Esm H88
An update for LibreOffice packages addresses multiple security issues. Launched on 15 Jan 2022 for Fedora 34 users.
OpenPGP signature status doesn't consider additional message content

Summary

OpenPGP signature status doesn't consider additional message content. (CVE-2021-4126)
Matrix chat library libolm bundled with Thunderbird vulnerable to a buffer overflow. (CVE-2021-44538)

References

- https://bugs.mageia.org/show_bug.cgi?id=29794

- https://www.thunderbird.net/en-US/thunderbird/91.4.1/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2021-55/

- https://www.cve.org/CVERecord?id=CVE-2021-4126

- https://www.cve.org/CVERecord?id=CVE-2021-44538

Resolution

SRPMS

- 8/core/thunderbird-91.4.1-1.mga8

- 8/core/thunderbird-l10n-91.4.1-1.mga8

Publication date: 23 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0584.html
Type: security
CVE: CVE-2021-4126, CVE-2021-44538

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here