thunderbird-91.9.0-3.el8.ML.1

エラータID: AXSA:2022-3175:06

Release date: 
Tuesday, May 10, 2022 - 04:19
Subject: 
thunderbird-91.9.0-3.el8.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Mozilla Thunderbird is a standalone mail and newsgroup client.

This update upgrades Thunderbird to version 91.9.0.

Security Fix(es):

* Mozilla: Bypassing permission prompt in nested browsing contexts
(CVE-2022-29909)
* Mozilla: iframe Sandbox bypass (CVE-2022-29911)
* Mozilla: Fullscreen notification bypass using popups (CVE-2022-29914)
* Mozilla: Leaking browser history with CSS variables (CVE-2022-29916)
* Mozilla: Memory safety bugs fixed in Firefox 100 and Firefox ESR 91.9
(CVE-2022-29917)
* Mozilla: Reader mode bypassed SameSite cookies (CVE-2022-29912)
* Mozilla: Speech Synthesis feature not properly disabled (CVE-2022-29913)
* Mozilla: Incorrect security status shown after viewing an attached email
(CVE-2022-1520)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

CVE-2022-1520
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
CVE-2022-29909
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
CVE-2022-29911
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
CVE-2022-29912
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
CVE-2022-29913
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
CVE-2022-29914
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
CVE-2022-29916
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
CVE-2022-29917
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. thunderbird-91.9.0-3.el8.ML.1.src.rpm
    MD5: 2da941406c23b6173ae88b448f263d84
    SHA-256: 981d04c9da5d1f80d0152166e97fb48bba743054e2e5ca3f421549fb282cdd63
    Size: 514.18 MB

Asianux Server 8 for x86_64
  1. thunderbird-91.9.0-3.el8.ML.1.x86_64.rpm
    MD5: c5cb9550c1c3149ce37f7a1428b000ec
    SHA-256: 8aa609358d9f424194c34b5fec972293db14a669854b011026d7b96c68c06f74
    Size: 100.52 MB