Lucene search

K
mageiaGentoo FoundationMGASA-2024-0050
HistoryFeb 27, 2024 - 4:21 a.m.

Updated thunderbird packages fix security vulnerabilities

2024-02-2704:21:38
Gentoo Foundation
advisories.mageia.org
19
thunderbird
security vulnerabilities
memory read
dialog spoofing
permission dialog
http responses
memory safety
unix

7.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.5%

The updated packages fix security vulnerabilities: Out-of-bounds memory read in networking channels. (CVE-2024-1546) Alert dialog could have been spoofed on another site. (CVE-2024-1547) Fullscreen Notification could have been hidden by select element. (CVE-2024-1548) Custom cursor could obscure the permission dialog. (CVE-2024-1549) Mouse cursor re-positioned unexpectedly could have led to unintended permission grants. (CVE-2024-1550) Multipart HTTP Responses would accept the Set-Cookie header in response parts. (CVE-2024-1551) Incorrect code generation on 32-bit ARM devices. (CVE-2024-1552) Memory safety bugs fixed in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. (CVE-2024-1553)