thunderbird-91.9.1-1.el9.ML.1

エラータID: AXSA:2022-4007:17

Release date: 
Monday, November 7, 2022 - 08:09
Subject: 
thunderbird-91.9.1-1.el9.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Mozilla Thunderbird is a standalone mail and newsgroup client.

This update upgrades Thunderbird to version 91.9.1.

Security Fix(es):

* Mozilla: Untrusted input used in JavaScript object indexing, leading to prototype pollution (CVE-2022-1529)
* Mozilla: Prototype pollution in Top-Level Await implementation (CVE-2022-1802)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2022-1529
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2022-1802
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. thunderbird-91.9.1-1.el9.ML.1.src.rpm
    MD5: 758ceb218386cc88f86186805a6ec857
    SHA-256: 9024477ce13a124511a95ac5653764ac07cc193b4ac142d27f81d3937eef9b66
    Size: 509.23 MB

Asianux Server 9 for x86_64
  1. thunderbird-91.9.1-1.el9.ML.1.x86_64.rpm
    MD5: 073f72a368efb1b3946a834f4a6b8e43
    SHA-256: 2cd51ef4bc2c62d3db84449c14446020d892583f84a23004d968d93f772378b7
    Size: 97.75 MB