Lucene search

K
altlinuxHttps://packages.altlinux.org/en/sisyphus/security/84C3EDB48DB6C101EE326383AB1B68B8
HistoryNov 24, 2022 - 12:00 a.m.

Security fix for the ALT Linux 10 package thunderbird version 102.5.0-alt1

2022-11-2400:00:00
https://packages.altlinux.org/en/sisyphus/security/
packages.altlinux.org
13
alt linux 10
thunderbird
security fixes
cve-2022-45403
cve-2022-45404
cve-2022-45405
cve-2022-45406
cve-2022-45408
cve-2022-45409
cve-2022-45410
cve-2022-45411
cve-2022-45412
cve-2022-45416
cve-2022-45418
cve-2022-45420
cve-2022-45421
memory safety bugs

EPSS

0.002

Percentile

59.3%

102.5.0-alt1 built Nov. 24, 2022 Pavel Vasenkov in task #310334

Nov. 16, 2022 Pavel Vasenkov

- New version.
- Security fixes:
  + CVE-2022-45403 Service Workers might have learned size of cross-origin media files
  + CVE-2022-45404 Fullscreen notification bypass
  + CVE-2022-45405 Use-after-free in InputStream implementation
  + CVE-2022-45406 Use-after-free of a JavaScript Realm
  + CVE-2022-45408 Fullscreen notification bypass via windowName
  + CVE-2022-45409 Use-after-free in Garbage Collection
  + CVE-2022-45410 ServiceWorker-intercepted requests bypassed SameSite cookie policy
  + CVE-2022-45411 Cross-Site Tracing was possible via non-standard override headers
  + CVE-2022-45412 Symlinks may resolve to partially uninitialized buffers
  + CVE-2022-45416 Keystroke Side-Channel Leakage
  + CVE-2022-45418 Custom mouse cursor could have been drawn over browser UI
  + CVE-2022-45420 Iframe contents could be rendered outside the iframe
  + CVE-2022-45421 Memory safety bugs fixed in Thunderbird 102.5