RHSA-2022:1725HighCVSS 9.8
Red Hat Security Advisory: thunderbird security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2022-1520 — Mozilla: Incorrect security status shown after viewing an attached email CVE-2022-29909 — Mozilla: Bypassing permission prompt in nested browsing contexts CVE-2022-29911 — Mozilla: iframe Sandbox bypass CVE-2022-29912 — Mozilla: Reader mode bypassed SameSite cookies CVE-2022-29913 — Mozilla: Speech Synthesis feature not properly disabled CVE-2022-29914 — Mozilla: Fullscreen notification bypass using popups CVE-2022-29916 — Mozilla: Leaking browser history with CSS variables CVE-2022-29917 — Mozilla: Memory safety bugs fixed in Firefox 100 and Firefox ESR 91.9
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2022:1725
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2081468
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2081469
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2081470
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2081471
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2081472
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2081473
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2082037
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2082038
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1725.json