MGASA-2023-0147
Dashboard / Vulnerabilities / MGASA-2023-0147
MGASA-2023-0147
Summary: Updated thunderbird packages fix security vulnerability
Details: Fullscreen notification obscured. (CVE-2023-29533) Double-free in libwebp. (MFSA-TMP-2023-0001) Potential Memory Corruption following Garbage Collector compaction. (CVE-2023-29535) Invalid free from JavaScript code. (CVE-2023-29536) Revocation status of S/Mime recipient certificates was not checked. (CVE-2023-0547) Hang when processing certain OpenPGP messages. (CVE-2023-29479) Content-Disposition filename truncation leads to Reflected File Download. (CVE-2023-29539) Files with malicious extensions could have been downloaded unsafely on Linux. (CVE-2023-29541) Memory Corruption in Safe Browsing Code. (CVE-2023-1945) Incorrect optimization result on ARM64. (CVE-2023-29548) Memory safety bugs fixed in Thunderbird 102.10. (CVE-2023-29550)
References: https://advisories.mageia.org/MGASA-2023-0147.html, https://bugs.mageia.org/show_bug.cgi?id=31787, https://www.thunderbird.net/en-US/thunderbird/102.10.0/releasenotes/, https://www.mozilla.org/en-US/security/advisories/mfsa2023-15/
Affected packages
Package
Name: thunderbird
Purl: pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
