-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Critical: thunderbird security update Advisory ID: RHSA-2022:4770-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:4770 Issue date: 2022-05-27 CVE Names: CVE-2022-1529 CVE-2022-1802 ===================================================================== 1. Summary: An update for thunderbird is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.1) - ppc64le, x86_64 3. Description: Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 91.9.1. Security Fix(es): * Mozilla: Untrusted input used in JavaScript object indexing, leading to prototype pollution (CVE-2022-1529) * Mozilla: Prototype pollution in Top-Level Await implementation (CVE-2022-1802) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of Thunderbird must be restarted for the update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2089217 - CVE-2022-1802 Mozilla: Prototype pollution in Top-Level Await implementation 2089218 - CVE-2022-1529 Mozilla: Untrusted input used in JavaScript object indexing, leading to prototype pollution 6. Package List: Red Hat Enterprise Linux AppStream E4S (v. 8.1): Source: thunderbird-91.9.1-1.el8_1.src.rpm ppc64le: thunderbird-91.9.1-1.el8_1.ppc64le.rpm thunderbird-debuginfo-91.9.1-1.el8_1.ppc64le.rpm thunderbird-debugsource-91.9.1-1.el8_1.ppc64le.rpm x86_64: thunderbird-91.9.1-1.el8_1.x86_64.rpm thunderbird-debuginfo-91.9.1-1.el8_1.x86_64.rpm thunderbird-debugsource-91.9.1-1.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-1529 https://access.redhat.com/security/cve/CVE-2022-1802 https://access.redhat.com/security/updates/classification/#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYpEx1NzjgjWX9erEAQj8jA/+L6C0GLnaChCCIBO2QJa6u1TWH3H8MsD1 bZE5hGvCD9/U+zh1ZahF+9wgTXsGxhvusoBam8yDfLHqe70M7hHZtddVlkVF2yQr 9Y0yjoWNx2hSBTbUDIO+Haegp6BoUmgTlrTjGnz/5gdr0Z/qTaYk56E1EYtQj0Y9 qHf7j+FXWleZ0n4+1np1dXcTwKChr1wEmp5+5cvRifwwyMsZkc9asHQa/SH6xFiw voE70Hjvc2SzPdF+hCpxu9qxBXa6aEfqpyVVgHrRvUY/RMnpSTG57lCKkVvZocWp KgT/AkRPHC9fAsiKg/CNYgocTua76hrd24UyuCPIVsh3KhwgwIX3DIYfsb4/3QPy P4Xs8tsAzfh0c0m0lOb1Dgb//YaqntOiD6b6VrMagwNXR+4vcnR4j2t0hQ8RRBCL ZYylbF5PfLjcERsMHIoUKupvApPRgvzeVuk6Fo6dfb1jig5NfoBO4mimbfMZ0bD8 syngbPVPrq1OhZskkFdT8CEbEVq238aeCiVqiG+6sgi5UVfoRuE0MtKqfhrbtNJp coCFOT6HOdsTdAexn8N2OvbRtXnztdaiOA1m9UiSrcSBiojBhIkzGuuMzv9H6tZ7 M+DdvWWoDVS/CcLzardhSejiwJXTBupKv0Tw6pAxkE96UnuRMHRFEvQmc1fsbTLN tcim65iKDz4= =Pxim -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce