RHSA-2024:1934: Low: thunderbird security update
Low: thunderbird security update
Other sources
Mozilla Thunderbird is a standalone mail and newsgroup client.This update upgrades Thunderbird to version 115.10.0.Security Fix(es): Mozilla: Denial of Service using HTTP/2 CONTINUATION frames (CVE-2024-3302) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1934?
The severity of RHSA-2024:1934 is classified as low.
How do I fix RHSA-2024:1934?
To fix RHSA-2024:1934, upgrade to Thunderbird version 115.10.0-2.el8_2 or later.
What vulnerability does RHSA-2024:1934 address?
RHSA-2024:1934 addresses a Denial of Service vulnerability using HTTP/2 CONTINUATION frames (CVE-2024-3302).
Which software is affected by RHSA-2024:1934?
RHSA-2024:1934 affects multiple versions of Mozilla Thunderbird on Red Hat Enterprise Linux.
Is user action required for RHSA-2024:1934?
Yes, user action is required to install the update in order to mitigate the vulnerability.