RHSA-2023:1401: Important: thunderbird security update
Mozilla Thunderbird is a standalone mail and newsgroup client.This update upgrades Thunderbird to version 102.9.0.Security Fix(es): Mozilla: Incorrect code generation during JIT compilation (CVE-2023-25751) Mozilla: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9 (CVE-2023-28176) Mozilla: Potential out-of-bounds when accessing throttled streams (CVE-2023-25752) Mozilla: Invalid downcast in Worklets (CVE-2023-28162) Mozilla: URL being dragged from a removed cross-origin iframe into the same tab triggered navigation (CVE-2023-28164) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What security issues does RHSA-2023:1401 address?
RHSA-2023:1401 addresses incorrect code generation during JIT compilation (CVE-2023-25751) and memory safety bugs in Mozilla Thunderbird.
How do I fix the vulnerabilities in RHSA-2023:1401?
To fix the vulnerabilities in RHSA-2023:1401, upgrade Thunderbird to version 102.9.0-1.el7_9.
What is the severity level of RHSA-2023:1401?
The severity level of RHSA-2023:1401 is considered significant due to the potential for code execution exploits.
Which versions of Thunderbird are affected by RHSA-2023:1401?
Versions of Thunderbird prior to 102.9.0-1.el7_9 are affected by RHSA-2023:1401.
Is there a specific Red Hat package version that resolves RHSA-2023:1401?
Yes, the specific Red Hat package version that resolves RHSA-2023:1401 is 102.9.0-1.el7_9.