Red Hat Security Advisory: thunderbird security update
🔗 CVE IDs covered (12)
📋 Description
CVE-2024-9392 — firefox: thunderbird: Compromised content process can bypass site isolation CVE-2024-9393 — firefox: thunderbird: Cross-origin access to PDF contents through multipart responses CVE-2024-9394 — firefox: thunderbird: Cross-origin access to JSON contents through multipart responses CVE-2024-9396 — firefox: thunderbird: Potential memory corruption may occur when cloning certain objects CVE-2024-9397 — firefox: thunderbird: Potential directory upload bypass via clickjacking CVE-2024-9398 — firefox: thunderbird: External protocol handlers could be enumerated via popups CVE-2024-9399 — firefox: thunderbird: Specially crafted WebTransport requests could lead to denial of service CVE-2024-9400 — firefox: thunderbird: Potential memory corruption during JIT compilation CVE-2024-9401 — firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 115.16, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 CVE-2024-9402 — firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 CVE-2024-9403 — firefox: thunderbird: Memory safety bugs fixed in Firefox 131 and Thunderbird 131 CVE-2024-9680 — firefox: Use-after-free in Animation timeline (128.3.1 ESR Chemspill)
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2024:8166
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2314431
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315945
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315947
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315949
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315950
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315951
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315952
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315953
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315954
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315956
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315957
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2317442
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8166.json