Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-7190

Опубликовано: 27 окт. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-7190: thunderbird security update (IMPORTANT)

[102.4.0-1.0.1]

  • Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js

[102.4.0-1]

  • Update to 102.4.0 build1

Связанные уязвимости

rocky
больше 2 лет назад

Important: thunderbird security update

oracle-oval
больше 2 лет назад

ELSA-2022-7184: thunderbird security update (IMPORTANT)

oracle-oval
больше 2 лет назад

ELSA-2022-7178: thunderbird security update (IMPORTANT)

suse-cvrf
больше 2 лет назад

Security update for MozillaThunderbird

CVSS3: 8.6
ubuntu
больше 2 лет назад

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. Starting with version 19.7.0, matrix-js-sdk has been modified to only accept Olm-encrypted to-device messages. Out of caution, several other checks have been audited or added. This at...