Mageia 2024-0006: thunderbird thunderbird-l10n security update
Summary
The updated packages fix security vulnerabilities:
Truncated signed text was shown with a valid OpenPGP signature.
(CVE-2023-50762)
S/MIME signature accepted despite mismatching message date.
(CVE-2023-50761)
Heap-buffer-overflow affecting WebGL DrawElementsInstanced method with
Mesa VM driver. (CVE-2023-6856)
Symlinks may resolve to smaller than expected buffers. (CVE-2023-6857)
Heap buffer overflow in nsTextFragment. (CVE-2023-6858)
Use-after-free in PR_GetIdentitiesLayer. (CVE-2023-6859)
Potential sandbox escape due to VideoBridge lack of texture validation.
(CVE-2023-6860)
Heap buffer overflow affected nsWindow::PickerOpen(void) in headless
mode. (CVE-2023-6861)
Use-after-free in nsDNSService. (CVE-2023-6862)
Undefined behavior in ShutdownObserver(). (CVE-2023-6863)
Memory safety bugs fixed in Firefox 121, Firefox ESR 115.6, and
Thunderbird 115.6. (CVE-2023-6864)
References
- https://bugs.mageia.org/show_bug.cgi?id=32643
- https://www.thunderbird.net/en-US/thunderbird/115.5.2/releasenotes/
- https://www.thunderbird.net/en-US/thunderbird/115.6.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-55/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6856
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6857
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6858
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6859
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6860
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6861
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6862
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6863
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6864
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50761
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50762
Resolution
MGASA-2024-0006 - Updated thunderbird thunderbird-l10n packages fix security vulnerabilities
SRPMS
- 9/core/thunderbird-115.6.0-1.mga9
- 9/core/thunderbird-l10n-115.6.0-1.mga9