thunderbird-115.6.0-1.el8_9.ML.1

エラータID: AXSA:2024-7381:03

Release date: 
Friday, January 12, 2024 - 09:41
Subject: 
thunderbird-115.6.0-1.el8_9.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Mozilla Thunderbird is a standalone mail and newsgroup client.

This update upgrades Thunderbird to version 115.6.0.

Security Fix(es):

Mozilla: Heap-buffer-overflow affecting WebGL
DrawElementsInstanced method with Mesa VM driver (CVE-2023-6856)
Mozilla: Memory safety bugs fixed in Firefox 121, Firefox ESR 115.6, and
Thunderbird 115.6 (CVE-2023-6864)
Mozilla: S/MIME signature accepted despite mismatching message date
(CVE-2023-50761)
Mozilla: Truncated signed text was shown with a valid OpenPGP signature
(CVE-2023-50762)
Mozilla: Symlinks may resolve to smaller than expected buffers
(CVE-2023-6857)
Mozilla: Heap buffer overflow in nsTextFragment (CVE-2023-6858)
Mozilla: Use-after-free in PR_GetIdentitiesLayer (CVE-2023-6859)
Mozilla: Potential sandbox escape due to VideoBridge lack of
texture validation (CVE-2023-6860)
Mozilla: Heap buffer overflow affected
nsWindow::PickerOpen(void) in headless mode (CVE-2023-6861)
Mozilla: Use-after-free in nsDNSService (CVE-2023-6862)
Mozilla: Undefined behavior in ShutdownObserver()
(CVE-2023-6863)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

CVE(s):
CVE-2023-6856
CVE-2023-6857
CVE-2023-6858
CVE-2023-6859
CVE-2023-6860
CVE-2023-6861
CVE-2023-6862
CVE-2023-6863
CVE-2023-6864
CVE-2023-50761
CVE-2023-50762

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. thunderbird-115.6.0-1.el8_9.ML.1.src.rpm
    MD5: c81b61cab840367db578273eb41c928d
    SHA-256: 666207da3c42a6fe21dd51f3746e4ba2b8708c6b031d78d54233970a43e07429
    Size: 704.92 MB

Asianux Server 8 for x86_64
  1. thunderbird-115.6.0-1.el8_9.ML.1.x86_64.rpm
    MD5: 2867ddf9a1d3bfd2b04e6ba2f57a8a46
    SHA-256: 17c398e7cb254554347834c964276bc51cdfcba2bf4474fddd0e19b758375101
    Size: 109.85 MB