RHSA-2022:6995: Important: thunderbird security update
Mozilla Thunderbird is a standalone mail and newsgroup client.This update upgrades Thunderbird to version 102.3.0.Security Fix(es): expat: a use-after-free in the doContent function in xmlparse.c (CVE-2022-40674) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 102.3.0-4.el8_4 - Upgrade
Upgrade
redhat/thunderbird-debuginfoto a version that resolves this vulnerability.Fixed in 102.3.0-4.el8_4 - Upgrade
Upgrade
redhat/thunderbird-debugsourceto a version that resolves this vulnerability.Fixed in 102.3.0-4.el8_4 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 102.3.0-4.el8_4.aa - Upgrade
Upgrade
redhat/thunderbird-debuginfoto a version that resolves this vulnerability.Fixed in 102.3.0-4.el8_4.aa - Upgrade
Upgrade
redhat/thunderbird-debugsourceto a version that resolves this vulnerability.Fixed in 102.3.0-4.el8_4.aa - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 102.3.0 - Operational
Restart all running instances of Thunderbird so the update to 102.3.0 takes effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:6995?
The severity of RHSA-2022:6995 is classified as important.
How do I fix RHSA-2022:6995?
You can fix RHSA-2022:6995 by upgrading Thunderbird to version 102.3.0-4.el8_4.
What vulnerability is addressed in RHSA-2022:6995?
RHSA-2022:6995 addresses a use-after-free vulnerability in the expat library, specifically CVE-2022-40674.
Which versions of Thunderbird are affected by RHSA-2022:6995?
Versions of Thunderbird prior to 102.3.0-4.el8_4 are affected by RHSA-2022:6995.
Is there a need for a system reboot after installing the fix for RHSA-2022:6995?
A system reboot is not typically required after applying the fix for RHSA-2022:6995, but it's advisable to restart the application.