Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 9: MGASA-2024-0191 Critical: Thunderbird Security Issues

mageia
Calendar Grey May 21, 2024
Dist Mageia Esm H88
Mozilla Thunderbird version 115.11 includes crucial updates addressing several vulnerabilities related to JavaScript execution and permission bypass vulnerabilities.
Arbitrary JavaScript execution in PDF.js

Summary

Arbitrary JavaScript execution in PDF.js. (CVE-2024-4367) IndexedDB files retained in private browsing mode. (CVE-2024-4767) Potential permissions request bypass via clickjacking. (CVE-2024-4768) Cross-origin responses could be distinguished between script and non-script content-types. (CVE-2024-4769) Use-after-free could occur when printing to PDF. (CVE-2024-4770) Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. (CVE-2024-4777)

References

- https://bugs.mageia.org/show_bug.cgi?id=33218

- https://www.thunderbird.net/en-US/thunderbird/115.11.0esr/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2024-23/

- https://www.cve.org/CVERecord?id=CVE-2024-4367

- https://www.cve.org/CVERecord?id=CVE-2024-4767

- https://www.cve.org/CVERecord?id=CVE-2024-4768

- https://www.cve.org/CVERecord?id=CVE-2024-4769

- https://www.cve.org/CVERecord?id=CVE-2024-4770

- https://www.cve.org/CVERecord?id=CVE-2024-4777

Resolution

SRPMS

- 9/core/thunderbird-115.11.0-1.mga9

- 9/core/thunderbird-l10n-115.11.0-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 21 May 2024
URL: https://advisories.mageia.org/MGASA-2024-0191.html
Type: security
CVE: CVE-2024-4367, CVE-2024-4767, CVE-2024-4768, CVE-2024-4769, CVE-2024-4770, CVE-2024-4777

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here