Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2021:4150-1 Important Update for MozillaThunderbird Security

suse
Calendar Grey December 22, 2021
Dist Suse Esm H88
Important notice for Firefox users regarding security patch encompassing 30 vulnerabilities. Immediate action is recommended!
An update that fixes 33 vulnerabilities is now available

Summary

This update for MozillaThunderbird fixes the following issues: - Update to version 91.4 MFSA 2021-54 (bsc#1193485) - CVE-2021-43536: URL leakage when navigating while executing asynchronous function - CVE-2021-43537: Heap buffer overflow when using structured clone - CVE-2021-43538: Missing fullscreen and pointer lock notification when requesting both - CVE-2021-43539: GC rooting failure when calling wasm instance methods - CVE-2021-43541: External protocol handler parameters were unescaped - CVE-2021-43542: XMLHttpRequest error codes could have leaked the existence of an external protocol handler - CVE-2021-43543: Bypass of CSP sandbox directive when embedding - CVE-2021-43545: Denial of Service when using the Location API in a loop

References

#1182863 #1189547 #1190244 #1190269 #1191332

#1192250 #1193485

Cross- CVE-2021-29981 CVE-2021-29982 CVE-2021-29987

CVE-2021-29991 CVE-2021-32810 CVE-2021-38492

CVE-2021-38493 CVE-2021-38495 CVE-2021-38496

CVE-2021-38497 CVE-2021-38498 CVE-2021-38500

CVE-2021-38501 CVE-2021-38502 CVE-2021-38503

CVE-2021-38504 CVE-2021-38505 CVE-2021-38506

CVE-2021-38507 CVE-2021-38508 CVE-2021-38509

CVE-2021-38510 CVE-2021-40529 CVE-2021-43528

CVE-2021-43536 CVE-2021-43537 CVE-2021-43538

CVE-2021-43539 CVE-2021-43541 CVE-2021-43542

CVE-2021-43543 CVE-2021-43545 CVE-2021-43546

CVSS scores:

CVE-2021-29991 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVE-2021-32810 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:4150-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here