thunderbird-115.14.0-1.el8_10.ML.1

エラータID: AXSA:2024-8693:19

Release date: 
Wednesday, August 21, 2024 - 13:55
Subject: 
thunderbird-115.14.0-1.el8_10.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Mozilla Thunderbird is a standalone mail and newsgroup client.

Security Fix(es):

* Thunderbird: 115.14/128.1
* mozilla: Fullscreen notification dialog can be obscured by document content (CVE-2024-7518)
* mozilla: Out of bounds memory access in graphics shared memory handling (CVE-2024-7519)
* mozilla: Type confusion in WebAssembly (CVE-2024-7520)
* mozilla: Incomplete WebAssembly exception handing (CVE-2024-7521)
* mozilla: Out of bounds read in editor component (CVE-2024-7522)
* mozilla: Missing permission check when creating a StreamFilter (CVE-2024-7525)
* mozilla: Uninitialized memory used by WebGL (CVE-2024-7526)
* mozilla: Use-after-free in JavaScript garbage collection (CVE-2024-7527)
* mozilla: Use-after-free in IndexedDB (CVE-2024-7528)
* mozilla: Document content could partially obscure security prompts (CVE-2024-7529)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-7518
Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVE-2024-7519
Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
CVE-2024-7520
A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVE-2024-7521
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
CVE-2024-7522
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
CVE-2024-7525
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
CVE-2024-7526
ANGLE failed to initialize parameters which led to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
CVE-2024-7527
Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
CVE-2024-7528
Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVE-2024-7529
The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. thunderbird-115.14.0-1.el8_10.ML.1.src.rpm
    MD5: 51471497ef15003c79a4898adc2603ce
    SHA-256: a0cf53200f71aa4a2c05a3ff8953c9026c315a11efa3f38edf1f0ae2d5542048
    Size: 704.52 MB

Asianux Server 8 for x86_64
  1. thunderbird-115.14.0-1.el8_10.ML.1.x86_64.rpm
    MD5: 2c12cb74f15204a473d987b97b1a44bd
    SHA-256: 71035402373492706257a13fd800e3e1899fa93c2304839c894de3c8fd765958
    Size: 111.42 MB