QID 257255

Date Published: 2023-11-29

QID 257255: CentOS Security Update for thunderbird

Mozilla thunderbird is a standalone mail and newsgroup client...Security Fix(es): mozilla: memory corruption in ipc canvastranslator (cve-2023-4573).
Mozilla: memory corruption in ipc colorpickershowncallback (cve-2023-4574).
Mozilla: memory corruption in ipc filepickershowncallback (cve-2023-4575).
Mozilla: memory corruption in jit updateregexpstatics (cve-2023-4577).
Mozilla: memory safety bugs fixed in firefox 117, firefox esr 102.15, firefox esr 115.2, thunderbird 102.15, and thunderbird 115.2 (cve-2023-4584).
Mozilla: memory safety bugs fixed in firefox 117, firefox esr 115.2, and thunderbird 115.2 (cve-2023-4585).
Mozilla: full screen notification obscured by file open dialog (cve-2023-4051).
Mozilla: full screen notification obscured by external program (cve-2023-4053).
Mozilla: error reporting methods in spidermonkey could have triggered an out of memory exception (cve-2023-4578).
Mozilla: push notifications saved to disk unencrypted (cve-2023-4580).
Mozilla: xll file extensions were downloadable without warnings (cve-2023-4581).
Mozilla: browsing context potentially not cleared when closing private window (cve-2023-4583). Affected Products CentOS linux 7 x86_64.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Centos mirror patch for updates and patch information.
    Software Advisories
    Advisory ID Software Component Link
    centos mirror URL Logo mirror.centos.org/centos/7/updates/x86_64/Packages/?C=M;O=D