Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 9 MGASA-2023-0309 High Severity: Thunderbird Clickjack Issues

mageia
Calendar Grey November 6, 2023
Dist Mageia Esm H88
Mozilla has released critical updates for Thunderbird, addressing various security flaws such as memory corruption and clickjacking vulnerabilities.
The updated packages fix security vulnerabilities: Queued up rendering could have allowed websites to clickjack

Summary

The updated packages fix security vulnerabilities:
Queued up rendering could have allowed websites to clickjack. (CVE-2023-5721)
Address bar spoofing via bidirectional characters. (CVE-2023-5732)
Large WebGL draw could have led to a crash. (CVE-2023-5724)
WebExtensions could open arbitrary URLs. (CVE-2023-5725)
Improper object tracking during GC in the JavaScript engine could have led to a crash. (CVE-2023-5728)
Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4.1. (CVE-2023-5730)

References

- https://bugs.mageia.org/show_bug.cgi?id=32478

- https://www.thunderbird.net/en-US/thunderbird/115.4.1/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2023-47/

- https://www.cve.org/CVERecord?id=CVE-2023-5721

- https://www.cve.org/CVERecord?id=CVE-2023-5732

- https://www.cve.org/CVERecord?id=CVE-2023-5724

- https://www.cve.org/CVERecord?id=CVE-2023-5725

- https://www.cve.org/CVERecord?id=CVE-2023-5728

- https://www.cve.org/CVERecord?id=CVE-2023-5730

Resolution

SRPMS

- 9/core/thunderbird-115.4.1-1.mga9

- 9/core/thunderbird-l10n-115.4.1-1.mga9

Publication date: 06 Nov 2023
URL: https://advisories.mageia.org/MGASA-2023-0309.html
Type: security
CVE: CVE-2023-5721, CVE-2023-5732, CVE-2023-5724, CVE-2023-5725, CVE-2023-5728, CVE-2023-5730

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here