-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2020:4155-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:4155 Issue date: 2020-10-01 CVE Names: CVE-2020-15673 CVE-2020-15676 CVE-2020-15677 CVE-2020-15678 ==================================================================== 1. Summary: An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, x86_64 3. Description: Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 78.3.1. Security Fix(es): * Mozilla: Memory safety bugs fixed in Firefox 81 and Firefox ESR 78.3 (CVE-2020-15673) * Mozilla: XSS when pasting attacker-controlled data into a contenteditable element (CVE-2020-15676) * Mozilla: Download origin spoofing via redirect (CVE-2020-15677) * Mozilla: When recursing through layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free scenario (CVE-2020-15678) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of Thunderbird must be restarted for the update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1881664 - CVE-2020-15677 Mozilla: Download origin spoofing via redirect 1881665 - CVE-2020-15676 Mozilla: XSS when pasting attacker-controlled data into a contenteditable element 1881666 - CVE-2020-15678 Mozilla: When recursing through layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free scenario 1881667 - CVE-2020-15673 Mozilla: Memory safety bugs fixed in Firefox 81 and Firefox ESR 78.3 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: thunderbird-78.3.1-1.el8_2.src.rpm aarch64: thunderbird-78.3.1-1.el8_2.aarch64.rpm thunderbird-debuginfo-78.3.1-1.el8_2.aarch64.rpm thunderbird-debugsource-78.3.1-1.el8_2.aarch64.rpm ppc64le: thunderbird-78.3.1-1.el8_2.ppc64le.rpm thunderbird-debuginfo-78.3.1-1.el8_2.ppc64le.rpm thunderbird-debugsource-78.3.1-1.el8_2.ppc64le.rpm x86_64: thunderbird-78.3.1-1.el8_2.x86_64.rpm thunderbird-debuginfo-78.3.1-1.el8_2.x86_64.rpm thunderbird-debugsource-78.3.1-1.el8_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-15673 https://access.redhat.com/security/cve/CVE-2020-15676 https://access.redhat.com/security/cve/CVE-2020-15677 https://access.redhat.com/security/cve/CVE-2020-15678 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX3XXk9zjgjWX9erEAQhYBg//VMujtBwtXRC10U7hPa4Rm5OXTB1mJMWj Xz0E4mIUJYCAmSCJ1fYLiSy4kAHFB2jIErzYG39X3u9D2ihwSfk8kP9XOdBw8Szs 4NkkCj4TQY32Y37GAOC8W6u/9+36HyUqk03Ab29u+uEfapiDyx6uQml3em2yoouz 1biZu4RqSO8UfeDTw8Vb79mDYrmVU1jwKZhJqKtk3FFQJHX44oA645pMilVDIWnc IQXMbesPZY6aorssXCiP+M3dM/sh5gUv40dxSlga1ZPwfeeyxwYiDmWPE360UbAf N/IQkR68vmVM6GJcLmtKpHmf0WpqIwR3viRDaMyFBNpg9cKacW/WwVj+9lR7HISQ u3670ppvqcLtk4L+VTThainDSTNOhYxukC4XYp3ZZ2akvI7jFmfIjEC/te1woOiK d1lAnyPBDwPpCl04DzmuCChfQhwVNHZh/Lg9u6gs+0tJl6KFZqlQyt388PMBCbq1 6VHSF3JGJkZDER5xz2q9NnlI6RIpT430Ppy1+Pxrf+6+35wmJv7szKqz5eDfD73i X5yDH77MuPg4NrdN2EU9c8XqXtdDSdbFzNnbBoAGf81WreevTvQ7VFx6o4w6I1Il NvMBYA/zQIqPBjwaFlWauSzqrptozTbiPh33c/tm6mEPF67BHJRG0TBLKz5CH69b 0mP0/OnfkTA=jq2p -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce