Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:2264

Опубликовано: 07 июн. 2021
Источник: rocky
Оценка: Important

Описание

Important: thunderbird security update

Mozilla Thunderbird is a standalone mail and newsgroup client.

This update upgrades Thunderbird to version 78.11.0.

Security Fix(es):

  • Mozilla: Memory safety bugs fixed in Firefox 89 and Firefox ESR 78.11 (CVE-2021-29967)

  • Mozilla: Thunderbird stored OpenPGP secret keys without master password protection (CVE-2021-29956)

  • Mozilla: Partial protection of inline OpenPGP message not indicated (CVE-2021-29957)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
thunderbirdx86_641.el8_4thunderbird-78.11.0-1.el8_4.x86_64.rpm
firefoxx86_643.el8_4firefox-78.11.0-3.el8_4.x86_64.rpm
thunderbirdx86_641.el8_4thunderbird-78.11.0-1.el8_4.x86_64.rpm
firefoxx86_643.el8_4firefox-78.11.0-3.el8_4.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 4 лет назад

ELSA-2021-2264: thunderbird security update (IMPORTANT)

oracle-oval
больше 4 лет назад

ELSA-2021-2263: thunderbird security update (IMPORTANT)

suse-cvrf
больше 4 лет назад

Security update for MozillaThunderbird

suse-cvrf
больше 4 лет назад

Security update for MozillaThunderbird

CVSS3: 4.3
ubuntu
больше 4 лет назад

OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master password protection was inactive for those keys. Version 78.10.2 will restore the protection mechanism for newly imported keys, and will automatically protect keys that had been imported using affected Thunderbird versions. This vulnerability affects Thunderbird < 78.10.2.