[Apollo] Advisories Statistics light light Login


Security Mirrored from RHSA-2024:1494
Issued at: 2024-03-27
Updated at: 2024-03-27


Moderate: thunderbird security update


Mozilla Thunderbird is a standalone mail and newsgroup client.

This update upgrades Thunderbird to version 115.9.0.

Security Fix(es):

* nss: timing attack against RSA decryption (CVE-2023-5388)

* Mozilla: Crash in NSS TLS method (CVE-2024-0743)

* Mozilla: Leaking of encrypted email subjects to other conversations (CVE-2024-1936)

* Mozilla: JIT code failed to save return registers on Armv7-A (CVE-2024-2607)

* Mozilla: Integer overflow could have led to out of bounds write


* Mozilla: Improper handling of html and body tags enabled CSP nonce leakage


* Mozilla: Clickjacking vulnerability could have led to a user accidentally

granting permissions (CVE-2024-2611)

* Mozilla: Self referencing object could have potentially led to a

use-after-free (CVE-2024-2612)

* Mozilla: Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and

Thunderbird 115.9 (CVE-2024-2614)

For more details about the security issue(s), including the impact, a CVSS

score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected products

Rocky Linux 8 aarch64 Rocky Linux 8 x86_64


2243644 2260012 2268171 2270660 2270661 2270663 2270664 2270665 2270666


CVE-2023-5388 CVE-2024-0743 CVE-2024-1936 CVE-2024-2607 CVE-2024-2608 CVE-2024-2610 CVE-2024-2611 CVE-2024-2612 CVE-2024-2614

Affected packages

Rocky Linux 8 aarch64 - AppStream

thunderbird-0:115.9.0-1.el8_9.aarch64.rpm thunderbird-0:115.9.0-1.el8_9.src.rpm thunderbird-debuginfo-0:115.9.0-1.el8_9.aarch64.rpm thunderbird-debugsource-0:115.9.0-1.el8_9.aarch64.rpm

Rocky Linux 8 x86_64 - AppStream

thunderbird-0:115.9.0-1.el8_9.src.rpm thunderbird-0:115.9.0-1.el8_9.x86_64.rpm thunderbird-debuginfo-0:115.9.0-1.el8_9.x86_64.rpm thunderbird-debugsource-0:115.9.0-1.el8_9.x86_64.rpm