firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 (CVE-2024-9402)
firefox: thunderbird: External protocol handlers could be enumerated via popups (CVE-2024-9398)
firefox: thunderbird: Potential memory corruption during JIT compilation (CVE-2024-9400)
firefox: thunderbird: Potential memory corruption may occur when cloning certain objects (CVE-2024-9396)
firefox: thunderbird: Cross-origin access to PDF contents through multipart responses (CVE-2024-9393)
firefox: thunderbird: Cross-origin access to JSON contents through multipart responses (CVE-2024-9394)
firefox: thunderbird: Compromised content process can bypass site isolation (CVE-2024-9392)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
ALSA-2024:7552: thunderbird security update (Important) Severity: Important Description Mozilla Thunderbird is a standalone mail and newsgroup client.
Security Fix(es):
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected packages: thunderbird-128.3.0-1.el9_4.aarch64 thunderbird-128.3.0-1.el9_4.ppc64le thunderbird-128.3.0-1.el9_4.s390x thunderbird-128.3.0-1.el9_4.x86_64