thunderbird-102.12.0-1.el8.ML.1

エラータID: AXSA:2023-6165:19

Release date: 
Thursday, June 29, 2023 - 00:40
Subject: 
thunderbird-102.12.0-1.el8.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Mozilla Thunderbird is a standalone mail and newsgroup client.

This update upgrades Thunderbird to version 102.12.0.

Security Fix(es):

* Mozilla: Click-jacking certificate exceptions through rendering lag (CVE-2023-34414)
* Mozilla: Memory safety bugs fixed in Firefox 114 and Firefox ESR 102.12 (CVE-2023-34416)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2023-34414
The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks that exploit human response time delays. If a malicious page elicited user clicks in precise locations immediately before navigating to a site with a certificate error and made the renderer extremely busy at the same time, it could create a gap between when the error page was loaded and when the display actually refreshed. With the right timing the elicited clicks could land in that gap and activate the button that overrides the certificate error for that site. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12.
CVE-2023-34416
Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. thunderbird-102.12.0-1.el8.ML.1.src.rpm
    MD5: 24f0642dff3077aaa5c136cd96e1ed01
    SHA-256: aadca07a201f5a99ca0cfb18e4f4a4b8643d7ab2451bf51722956e44b6619508
    Size: 617.01 MB

Asianux Server 8 for x86_64
  1. thunderbird-102.12.0-1.el8.ML.1.x86_64.rpm
    MD5: cfc032eddf697fa0494c7eba60bfec0b
    SHA-256: 44066cd98172cd9f50f2e74e569c5ba942c999db126c9679ac59e76e12cede96
    Size: 104.97 MB