thunderbird-78.13.0-1.el8.ML.1

エラータID: AXSA:2021-2370:15

Release date: 
Wednesday, August 18, 2021 - 03:44
Subject: 
thunderbird-78.13.0-1.el8.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Mozilla Thunderbird is a standalone mail and newsgroup client.

This update upgrades Thunderbird to version 78.13.0.

Security Fix(es):

* Mozilla: Uninitialized memory in a canvas object could have led to memory corruption (CVE-2021-29980)
* Mozilla: Incorrect instruction reordering during JIT optimization (CVE-2021-29984)
* Mozilla: Race condition when resolving DNS names could have led to memory corruption (CVE-2021-29986)
* Mozilla: Memory corruption as a result of incorrect style treatment (CVE-2021-29988)
* Mozilla: Memory safety bugs fixed in Thunderbird 78.13 (CVE-2021-29989)
* Mozilla: Use-after-free media channels (CVE-2021-29985)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2021-29980
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2021-29984
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2021-29985
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2021-29986
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2021-29988
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2021-29989
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. thunderbird-78.13.0-1.el8.ML.1.src.rpm
    MD5: 9fdf0ecab4600eb3b899474b9e88a9e8
    SHA-256: 80d6538c5c8243c387c5f785be5a0d3f2406c6275e40e4392d961e1f5bfa1c84
    Size: 688.32 MB

Asianux Server 8 for x86_64
  1. thunderbird-78.13.0-1.el8.ML.1.x86_64.rpm
    MD5: 9520c8c2215826b87196af1a80d5bc23
    SHA-256: 3496470d5905b72d57867ac21fc6ef3c1221e9efb243ed2e3e9a896a6d1563d8
    Size: 93.10 MB