RHSA-2024:2913: Important: thunderbird security update
Important: thunderbird security update
Other sources
Mozilla Thunderbird is a standalone mail and newsgroup client.<br>This update upgrades Thunderbird to version 115.11.0.<br>Security Fix(es):<br><li> firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367)</li> <li> firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767)</li> <li> firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768)</li> <li> firefox: Cross-origin responses could be distinguished between script and</li> non-script content-types (CVE-2024-4769)<br><li> firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770)</li> <li> firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and</li> Thunderbird 115.11 (CVE-2024-4777)<br>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2913?
The severity of RHSA-2024:2913 is classified as Important.
How do I fix RHSA-2024:2913?
To fix RHSA-2024:2913, upgrade Thunderbird to version 115.11.0-1.el7_9.
What software does RHSA-2024:2913 affect?
RHSA-2024:2913 affects multiple Red Hat Enterprise Linux products, including Desktop, Server, and Workstation.
What vulnerabilities are addressed in RHSA-2024:2913?
RHSA-2024:2913 addresses security issues including arbitrary JavaScript execution in PDF.js (CVE-2024-4367).
Is RHSA-2024:2913 related to other Red Hat security advisories?
Yes, RHSA-2024:2913 may be related to other Red Hat advisories as it addresses vulnerabilities in components used by various Red Hat products.