Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 9 Advisory 2024-0231 Moderate: Thunderbird Security Fixes

mageia
Calendar Grey June 22, 2024
Dist Mageia Esm H88
Enhanced Thunderbird releases tackle multiple vulnerabilities, such as race conditions and potential sandbox evasion risks.
Use-after-free in networking

Summary

Use-after-free in networking. (CVE-2024-5702) Use-after-free in JavaScript object transplant. (CVE-2024-5688) External protocol handlers leaked by timing attack. (CVE-2024-5690) Sandboxed iframes were able to bypass sandbox restrictions to open a new window. (CVE-2024-5691) Cross-Origin Image leak via Offscreen Canvas. (CVE-2024-5693) Memory Corruption in Text Fragments. (CVE-2024-5696) Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. (CVE-2024-5700)

References

- https://bugs.mageia.org/show_bug.cgi?id=33311

- https://www.thunderbird.net/en-US/thunderbird/115.12.0esr/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2024-28/

- https://www.cve.org/CVERecord?id=CVE-2024-5702

- https://www.cve.org/CVERecord?id=CVE-2024-5688

- https://www.cve.org/CVERecord?id=CVE-2024-5690

- https://www.cve.org/CVERecord?id=CVE-2024-5691

- https://www.cve.org/CVERecord?id=CVE-2024-5693

- https://www.cve.org/CVERecord?id=CVE-2024-5696

- https://www.cve.org/CVERecord?id=CVE-2024-5700

Resolution

SRPMS

- 9/core/thunderbird-115.12.0-1.mga9

- 9/core/thunderbird-l10n-115.12.0-1.mga9

Publication date: 22 Jun 2024
URL: https://advisories.mageia.org/MGASA-2024-0231.html
Type: security
CVE: CVE-2024-5702, CVE-2024-5688, CVE-2024-5690, CVE-2024-5691, CVE-2024-5693, CVE-2024-5696, CVE-2024-5700

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here