INFSA-2024:6684: Mozilla Thunderbird security update
Information about definition
Identificator: INFSA-2024:6684
Type: security
Release date: 2024-09-20 19:17:45 UTC
Information about package
Mozilla Thunderbird is a standalone mail and newsgroup client.
Vulnerabilities description
- CVE-2024-7652
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes this flaw as follows: An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash.
- CVE-2024-8381
The Mozilla Foundation's Security Advisory: A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the with environment.
- CVE-2024-8382
The Mozilla Foundation's Security Advisory: Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools console.
- CVE-2024-8384
The Mozilla Foundation's Security Advisory: The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption.
- CVE-2024-8385
The Mozilla Foundation's Security Advisory: A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability.
- CVE-2024-8386
The Mozilla Foundation's Security Advisory: If a site had been granted permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack.
- CVE-2024-8387
The Mozilla Foundation's Security Advisory: Memory safety bugs are present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort, some of these could have been exploited to run arbitrary code.
- CVE-2024-8394
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes this flaw as follows: When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2024-7652
|
no information | 8.6 | no information |
NIST — CVE-2024-8381
|
no information | 7.3 | no information |
NIST — CVE-2024-8382
|
no information | 8.8 | no information |
NIST — CVE-2024-8384
|
no information | 9.8 | no information |
NIST — CVE-2024-8385
|
no information | 9.8 | no information |
NIST — CVE-2024-8386
|
no information | 6.1 | no information |
NIST — CVE-2024-8387
|
no information | 9.8 | no information |
NIST — CVE-2024-8394
|
no information | 6.5 | no information |
Updated packages