USN-6840-1: Thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were tricked into opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass security restrictions, cross-site tracing, or execute arbitrary code.(CVE-2024-5688, CVE-2024-5690, CVE-2024-5696, CVE-2024-5700, CVE-2024-5702) Luan Herrera discovered that Thunderbird did not properly validate the X-Frame-Options header inside sandboxed iframe. An attacker could potentially exploit this issue to bypass sandbox restrictions to open a new window. (CVE-2024-5691) Kirtikumar Anandrao Ramchandani discovered that Thunderbird did not properly track cross-origin tainting in Offscreen Canvas. An attacker could potentially exploit this issue to access image data from another site in violation of same-origin policy. (CVE-2024-5693)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6840-1?
USN-6840-1 addresses multiple security issues in Thunderbird which could lead to denial of service or exposure of sensitive information.
How do I fix USN-6840-1?
To fix USN-6840-1, you need to update Thunderbird to the latest version specified in the advisory for your Ubuntu release.
What versions of Thunderbird are affected by USN-6840-1?
USN-6840-1 affects specific versions of Thunderbird for Ubuntu 20.04, 22.04, and 23.10.
What vulnerabilities are addressed in USN-6840-1?
USN-6840-1 resolves several security vulnerabilities that could potentially be exploited through specially crafted websites.
Is it safe to use Thunderbird after USN-6840-1?
If you have upgraded to the patched version of Thunderbird, it is safe to use following the remediation of USN-6840-1.