This update for MozillaThunderbird fixes the following issues: - Update to version 91.4 MFSA 2021-54 (bsc#1193485) - CVE-2021-43536: URL leakage when navigating while executing asynchronous function - CVE-2021-43537: Heap buffer overflow when using structured clone - CVE-2021-43538: Missing fullscreen and pointer lock notification when requesting both - CVE-2021-43539: GC rooting failure when calling wasm instance methods - CVE-2021-43541: External protocol handler parameters were unescaped - CVE-2021-43542: XMLHttpRequest error codes could have leaked the existence of an external protocol handler - CVE-2021-43543: Bypass of CSP sandbox directive when embedding - CVE-2021-43545: Denial of Service when using the Location API in a loop
#1182863 #1189547 #1190244 #1190269 #1191332
#1192250 #1193485
Cross- CVE-2021-29981 CVE-2021-29982 CVE-2021-29987
CVE-2021-29991 CVE-2021-32810 CVE-2021-38492
CVE-2021-38493 CVE-2021-38495 CVE-2021-38496
CVE-2021-38497 CVE-2021-38498 CVE-2021-38500
CVE-2021-38501 CVE-2021-38502 CVE-2021-38503
CVE-2021-38504 CVE-2021-38505 CVE-2021-38506
CVE-2021-38507 CVE-2021-38508 CVE-2021-38509
CVE-2021-38510 CVE-2021-40529 CVE-2021-43528
CVE-2021-43536 CVE-2021-43537 CVE-2021-43538
CVE-2021-43539 CVE-2021-43541 CVE-2021-43542
CVE-2021-43543 CVE-2021-43545 CVE-2021-43546
CVSS scores:
CVE-2021-29991 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVE-2021-32810 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get the latest Linux and open source security news straight to your inbox.