RHSA-2022:0853: Important: thunderbird security update
Mozilla Thunderbird is a standalone mail and newsgroup client.This update upgrades Thunderbird to version 91.7.0.Security Fix(es): Mozilla: Use-after-free in XSLT parameter processing (CVE-2022-26485) Mozilla: Use-after-free in WebGPU IPC Framework (CVE-2022-26486) expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235) expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution (CVE-2022-25236) expat: Integer overflow in storeRawNames() (CVE-2022-25315) Mozilla: Use-after-free in text reflows (CVE-2022-26381) Mozilla: Browser window spoof using fullscreen mode (CVE-2022-26383) Mozilla: iframe allow-scripts sandbox bypass (CVE-2022-26384) Mozilla: Time-of-check time-of-use bug when verifying add-on signatures (CVE-2022-26387) thunderbird: Crafted email could trigger an out-of-bounds write (CVE-2022-0566) Mozilla: Temporary files downloaded to /tmp and accessible by other local users (CVE-2022-26386) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 91.7.0-2.el8_4 - Upgrade
Upgrade
redhat/thunderbird-debuginfoto a version that resolves this vulnerability.Fixed in 91.7.0-2.el8_4 - Upgrade
Upgrade
redhat/thunderbird-debugsourceto a version that resolves this vulnerability.Fixed in 91.7.0-2.el8_4 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 91.7.0-2.el8_4.aa - Upgrade
Upgrade
redhat/thunderbird-debuginfoto a version that resolves this vulnerability.Fixed in 91.7.0-2.el8_4.aa - Upgrade
Upgrade
redhat/thunderbird-debugsourceto a version that resolves this vulnerability.Fixed in 91.7.0-2.el8_4.aa - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 91.7.0 - Operational
All running instances of Thunderbird must be restarted for the update to take effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0853?
RHSA-2022:0853 is classified as a moderate vulnerability affecting Mozilla Thunderbird.
How do I fix RHSA-2022:0853?
To fix RHSA-2022:0853, upgrade Mozilla Thunderbird to version 91.7.0-2.el8_4.
What are the vulnerabilities addressed in RHSA-2022:0853?
RHSA-2022:0853 addresses use-after-free vulnerabilities found in XSLT parameter processing and WebGPU IPC Framework.
Which versions of Thunderbird are affected by RHSA-2022:0853?
Versions of Thunderbird prior to 91.7.0-2.el8_4 are affected by RHSA-2022:0853.
Is RHSA-2022:0853 applicable to all operating systems?
RHSA-2022:0853 specifically affects Red Hat Enterprise Linux environments where Thunderbird is deployed.