Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia 8 MGASA-2023-0147 Critical: Thunderbird Memory Issues

mageia
Calendar Grey April 15, 2023
Dist Mageia Esm H88
Recent Thunderbird updates address significant vulnerabilities, including memory leaks and notification failures in Mageia 8.
Fullscreen notification obscured

Summary

Fullscreen notification obscured. (CVE-2023-29533) Double-free in libwebp. (MFSA-TMP-2023-0001) Potential Memory Corruption following Garbage Collector compaction. (CVE-2023-29535) Invalid free from JavaScript code. (CVE-2023-29536) Revocation status of S/Mime recipient certificates was not checked. (CVE-2023-0547) Hang when processing certain OpenPGP messages. (CVE-2023-29479) Content-Disposition filename truncation leads to Reflected File Download. (CVE-2023-29539) Files with malicious extensions could have been downloaded unsafely on Linux. (CVE-2023-29541) Memory Corruption in Safe Browsing Code. (CVE-2023-1945) Incorrect optimization result on ARM64. (CVE-2023-29548) Memory safety bugs fixed in Thunderbird 102.10. (CVE-2023-29550)

References

- https://bugs.mageia.org/show_bug.cgi?id=31787

- https://www.thunderbird.net/en-US/thunderbird/102.10.0/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2023-15/

- https://www.cve.org/CVERecord?id=CVE-2023-29533

- https://www.cve.org/CVERecord?id=CVE-2023-29535

- https://www.cve.org/CVERecord?id=CVE-2023-29536

- https://www.cve.org/CVERecord?id=CVE-2023-0547

- https://www.cve.org/CVERecord?id=CVE-2023-29479

- https://www.cve.org/CVERecord?id=CVE-2023-29539

- https://www.cve.org/CVERecord?id=CVE-2023-29541

- https://www.cve.org/CVERecord?id=CVE-2023-1945

- https://www.cve.org/CVERecord?id=CVE-2023-29548

- https://www.cve.org/CVERecord?id=CVE-2023-29550

Resolution

SRPMS

- 8/core/thunderbird-102.10.0-1.mga8

- 8/core/thunderbird-l10n-102.10.0-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 15 Apr 2023
URL: https://advisories.mageia.org/MGASA-2023-0147.html
Type: security
CVE: CVE-2023-29533, CVE-2023-29535, CVE-2023-29536, CVE-2023-0547, CVE-2023-29479, CVE-2023-29539, CVE-2023-29541, CVE-2023-1945, CVE-2023-29548, CVE-2023-29550

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here