The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-8203 http://linux.oracle.com/errata/ELSA-2025-8203.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: thunderbird-128.10.1-1.0.1.el9_6.x86_64.rpm aarch64: thunderbird-128.10.1-1.0.1.el9_6.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//thunderbird-128.10.1-1.0.1.el9_6.src.rpm Related CVEs: CVE-2025-3875 CVE-2025-3877 CVE-2025-3909 CVE-2025-3932 Description of changes: [128.10.1-1.0.1] - Fix prefs for new nss [Orabug: 37079813] - Add Oracle prefs [128.10.1] - Add OpenELA debranding [128.10.1-1] - Update to 128.10.1 _______________________________________________ El-errata mailing list
Memory corruption in WebGL API. (CVE-2024-6600) Race condition in permission assignment. (CVE-2024-6601) Memory corruption in thread creation. (CVE-2024-6603) Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13. (CVE-2024-6604) . MGASA-2024-0274 - Updated thunderbird packages fix security vulnerabilities Publication date: 21 Jul 2024 URL: https://advisories.mageia.org/MGASA-2024-0274.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-6600, CVE-2024-6601, CVE-2024-6603, CVE-2024-6604 Memory corruption in WebGL API. (CVE-2024-6600) Race condition in permission assignment. (CVE-2024-6601) Memory corruption in thread creation. (CVE-2024-6603) Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13. (CVE-2024-6604) References: - https://bugs.mageia.org/show_bug.cgi?id=33406 - https://www.thunderbird.net/en-US/thunderbird/115.13.0esr/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2024-31/ - https://www.cve.org/CVERecord?id=CVE-2024-6600 - https://www.cve.org/CVERecord?id=CVE-2024-6601 - https://www.cve.org/CVERecord?id=CVE-2024-6603 - https://www.cve.org/CVERecord?id=CVE-2024-6604 SRPMS: - 9/core/thunderbird-115.13.0-1.mga9 - 9/core/thunderbird-l10n-115.13.0-1.mga9 . The latest Thunderbird updates address vulnerabilities in Mageia versions, fixing serious memory leaks and enhancing system performance.. Thunderbird Security,Mageia Updates,Memory Corruption Fix,Firefox ESR Security. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-0456 https://linux.oracle.com/errata/ELSA-2023-0456.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: thunderbird-102.7.1-1.0.1.el7_9.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//thunderbird-102.7.1-1.0.1.el7_9.src.rpm Related CVEs: CVE-2022-46871 CVE-2022-46877 CVE-2023-23598 CVE-2023-23599 CVE-2023-23601 CVE-2023-23602 CVE-2023-23603 CVE-2023-23605 Description of changes: [102.7.1-1.0.1] - Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js - Enabled aarch64 build [102.7.1-1] - Update to 102.7.1 build1 [102.7.0-1] - Update to 102.7.0 build1 _______________________________________________ El-errata mailing list
New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and - -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] mozilla-thunderbird (SSA:2016-187-01) New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and - -current to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/mozilla-thunderbird-45.2.0-i586-1_slack14.2.txz: Upgraded. This release contains security fixes and improvements. For more information, see: https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/ (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.1 package: a0dc64a4bf928c7aab1f8dcc283d603b mozilla-thunderbird-45.2.0-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 4ff4d4d7baafbfd830a964c6fa5d62e7 mozilla-thunderbird-45.2.0-x86_64-1_slack14.1.txz Slackware 14.2 package: 3fbf549ffb6fbfab52c23f45dda9753d mozilla-thunderbird-45.2.0-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 2ac3f94cba6c6f2d39158c9a222ba750 mozilla-thunderbird-45.2.0-x86_64-1_slack14.2.txz Slackware -current package: 3fbf549ffb6fbfab52c23f45dda9753d xap/mozilla-thunderbird-45.2.0-i586-1.txz Slackware x86_64 -current package: 2ac3f94cba6c6f2d39158c9a222ba750 xap/mozilla-thunderbird-45.2.0-x86_64-1.txz Installation instructions: +------------------------+ Upgrade thepackage as root: # upgradepkg mozilla-thunderbird-45.2.0-i586-1_slack14.2.txz +-----+ . Latest Mozilla Thunderbird updates for Slackware bolster security through essential patches and enhancements.. Mozilla Thunderbird, Slackware Packages, Security Update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.