[Apollo] Advisories Statistics light light Login

RLSA-2023:7500

Security Mirrored from RHSA-2023:7500
Issued at: 2023-11-28
Updated at: 2023-11-28

Synopsis

Important: thunderbird security update



Description

Mozilla Thunderbird is a standalone mail and newsgroup client.

This update upgrades Thunderbird to version 115.5.0.

Security Fix(es):

* Mozilla: Out-of-bound memory access in WebGL2 blitFramebuffer (CVE-2023-6204)

* Mozilla: Use-after-free in MessagePort::Entangled (CVE-2023-6205)

* Mozilla: Clickjacking permission prompts using the fullscreen transition (CVE-2023-6206)

* Mozilla: Use-after-free in ReadableByteStreamQueueEntry::Buffer (CVE-2023-6207)

* Mozilla: Memory safety bugs fixed in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5 (CVE-2023-6212)

* Mozilla: Using Selection API would copy contents into X11 primary selection. (CVE-2023-6208)

* Mozilla: Incorrect parsing of relative URLs starting with "///" (CVE-2023-6209)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 8 aarch64

Fixes

2250896 2250897 2250898 2250899 2250900 2250901 2250902

CVEs

CVE-2023-6204 CVE-2023-6205 CVE-2023-6206 CVE-2023-6207 CVE-2023-6208 CVE-2023-6209 CVE-2023-6212

Affected packages

Rocky Linux 8 aarch64 - AppStream

thunderbird-0:115.5.0-1.el8_9.aarch64.rpm thunderbird-0:115.5.0-1.el8_9.src.rpm thunderbird-debuginfo-0:115.5.0-1.el8_9.aarch64.rpm thunderbird-debugsource-0:115.5.0-1.el8_9.aarch64.rpm