INFSA-2024:6684: Mozilla Thunderbird security update

Information about definition

Identificator: INFSA-2024:6684

Type: security

Release date: 2024-09-20 19:17:45 UTC

Information about package

Mozilla Thunderbird is a standalone mail and newsgroup client.

Vulnerabilities description

  • CVE-2024-7652

    A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes this flaw as follows: An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash.

  • CVE-2024-8381

    The Mozilla Foundation's Security Advisory: A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the with environment.

  • CVE-2024-8382

    The Mozilla Foundation's Security Advisory: Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools console.

  • CVE-2024-8384

    The Mozilla Foundation's Security Advisory: The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption.

  • CVE-2024-8385

    The Mozilla Foundation's Security Advisory: A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability.

  • CVE-2024-8386

    The Mozilla Foundation's Security Advisory: If a site had been granted permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack.

  • CVE-2024-8387

    The Mozilla Foundation's Security Advisory: Memory safety bugs are present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort, some of these could have been exploited to run arbitrary code.

  • CVE-2024-8394

    A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes this flaw as follows: When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
NIST — CVE-2024-7652
no information 8.6 no information
NIST — CVE-2024-8381
no information 7.3 no information
NIST — CVE-2024-8382
no information 8.8 no information
NIST — CVE-2024-8384
no information 9.8 no information
NIST — CVE-2024-8385
no information 9.8 no information
NIST — CVE-2024-8386
no information 6.1 no information
NIST — CVE-2024-8387
no information 9.8 no information
NIST — CVE-2024-8394
no information 6.5 no information
Critical, important, moderate, low

Updated packages