thunderbird-115.13.0-3.el9_4.ML.1

エラータID: AXSA:2024-8587:16

Release date: 
Monday, July 22, 2024 - 17:25
Subject: 
thunderbird-115.13.0-3.el9_4.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Mozilla Thunderbird is a standalone mail and newsgroup client.

Security Fix(es):

* Mozilla: Race condition in permission assignment (CVE-2024-6601)
* Mozilla: Memory corruption in thread creation (CVE-2024-6603)
* Mozilla: Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 (CVE-2024-6604)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-6601
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
CVE-2024-6603
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
CVE-2024-6604
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. thunderbird-115.13.0-3.el9_4.ML.1.src.rpm
    MD5: 34fa0f4c38f27ada2be77d7fbfbbb0ee
    SHA-256: e6e74456ab60e5a402d1fa2ad6172f6f868f39ba4c168577eef1ab433aa9e7ae
    Size: 704.92 MB

Asianux Server 9 for x86_64
  1. thunderbird-115.13.0-3.el9_4.ML.1.x86_64.rpm
    MD5: 2f3ab8abb8d5ec09f1c87cc7a0796ff2
    SHA-256: 29a192543e1c110ac3ce60fdc797859fed1de116ee086f687f9d5b56683c0960
    Size: 108.56 MB