MGASA-2024-0332 - Updated thunderbird packages fix security vulnerabilities

Publication date: 14 Oct 2024
URL: https://advisories.mageia.org/MGASA-2024-0332.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-7519,
     CVE-2024-7520,
     CVE-2024-7521,
     CVE-2024-7522,
     CVE-2024-7524,
     CVE-2024-7525,
     CVE-2024-7526,
     CVE-2024-7527,
     CVE-2024-7528,
     CVE-2024-7529,
     CVE-2024-7531,
     CVE-2024-8385,
     CVE-2024-8381,
     CVE-2024-8382,
     CVE-2024-8383,
     CVE-2024-8384,
     CVE-2024-8386,
     CVE-2024-8387

The current version has reached EOL and several security vulnerabilities were
fixed by Mozilla.
We are having some issues that are delaying the build for some
architectures, so for the moment we are releasing this update just for
x86_64.

References:
- https://bugs.mageia.org/show_bug.cgi?id=33502
- https://www.thunderbird.net/en-US/thunderbird/128.1.0esr/releasenotes/
- https://www.thunderbird.net/en-US/thunderbird/128.1.1esr/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-37/
- https://www.thunderbird.net/en-US/thunderbird/128.2.0esr/releasenotes/
- https://www.thunderbird.net/en-US/thunderbird/128.2.1esr/releasenotes/
- https://www.thunderbird.net/en-US/thunderbird/128.2.2esr/releasenotes/
- https://www.thunderbird.net/en-US/thunderbird/128.2.3esr/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-43/
- https://www.thunderbird.net/en-US/thunderbird/128.3.0esr/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-49/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7519
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7520
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7521
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7522
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7524
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7525
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7526
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7527
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7528
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7529
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7531
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8385
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8381
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8382
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8383
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8384
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8386
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8387

SRPMS:
- 9/core/thunderbird-128.3.0-1.mga9
- 9/core/thunderbird-l10n-128.3.0-1.mga9

Mageia 2024-0332: thunderbird Security Advisory Updates

The current version has reached EOL and several security vulnerabilities were fixed by Mozilla

Summary

The current version has reached EOL and several security vulnerabilities were fixed by Mozilla. We are having some issues that are delaying the build for some architectures, so for the moment we are releasing this update just for x86_64.

References

- https://bugs.mageia.org/show_bug.cgi?id=33502

- https://www.thunderbird.net/en-US/thunderbird/128.1.0esr/releasenotes/

- https://www.thunderbird.net/en-US/thunderbird/128.1.1esr/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2024-37/

- https://www.thunderbird.net/en-US/thunderbird/128.2.0esr/releasenotes/

- https://www.thunderbird.net/en-US/thunderbird/128.2.1esr/releasenotes/

- https://www.thunderbird.net/en-US/thunderbird/128.2.2esr/releasenotes/

- https://www.thunderbird.net/en-US/thunderbird/128.2.3esr/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2024-43/

- https://www.thunderbird.net/en-US/thunderbird/128.3.0esr/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2024-49/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7519

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7520

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7521

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7522

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7524

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7525

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7526

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7527

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7528

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7529

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7531

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8385

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8381

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8382

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8383

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8384

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8386

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8387

Resolution

MGASA-2024-0332 - Updated thunderbird packages fix security vulnerabilities

SRPMS

- 9/core/thunderbird-128.3.0-1.mga9

- 9/core/thunderbird-l10n-128.3.0-1.mga9

Severity
Publication date: 14 Oct 2024
URL: https://advisories.mageia.org/MGASA-2024-0332.html
Type: security
CVE: CVE-2024-7519, CVE-2024-7520, CVE-2024-7521, CVE-2024-7522, CVE-2024-7524, CVE-2024-7525, CVE-2024-7526, CVE-2024-7527, CVE-2024-7528, CVE-2024-7529, CVE-2024-7531, CVE-2024-8385, CVE-2024-8381, CVE-2024-8382, CVE-2024-8383, CVE-2024-8384, CVE-2024-8386, CVE-2024-8387

Related News