Lucene search

K
altlinuxHttps://packages.altlinux.org/en/sisyphus/security/9CC7328C94EF0123E6AE5C0BBC583AD2
HistoryOct 09, 2022 - 12:00 a.m.

Security fix for the ALT Linux 10 package thunderbird version 102.3.0-alt1

2022-10-0900:00:00
https://packages.altlinux.org/en/sisyphus/security/
packages.altlinux.org
7
alt linux 10
cve-2022-3266
cve-2022-40959
cve-2022-40960
cve-2022-40958
cve-2022-40956
cve-2022-40957
cve-2022-3155
cve-2022-40962
unix

0.002 Low

EPSS

Percentile

56.7%

Oct. 9, 2022 Pavel Vasenkov 102.3.0-alt1

- New version.
- Security fixes:
  + CVE-2022-3266 Out of bounds read when decoding H264
  + CVE-2022-40959 Bypassing FeaturePolicy restrictions on transient pages
  + CVE-2022-40960 Data-race when parsing non-UTF-8 URLs in threads
  + CVE-2022-40958 Bypassing Secure Context restriction for cookies with __Host and __Secure prefix
  + CVE-2022-40956 Content-Security-Policy base-uri bypass
  + CVE-2022-40957 Incoherent instruction cache when building WASM on ARM64
  + CVE-2022-3155 Attachment files saved to disk on macOS could be executed without warning
  + CVE-2022-40962 Memory safety bugs fixed in Thunderbird 102.3