Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 794085 - <mail-client/thunderbird{,-bin}-78.11.0: multiple vulnerabilities
Summary: <mail-client/thunderbird{,-bin}-78.11.0: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2 [glsa+]
Keywords:
Depends on:
Blocks: CVE-2021-29967
  Show dependency tree
 
Reported: 2021-06-04 02:07 UTC by John Helmert III
Modified: 2022-08-10 04:26 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-06-04 02:07:08 UTC
See tracker for details. Highest severity bug is CVE-2021-29967:

Mozilla developers Gabriele Svelto, Anny Gakhokidze, Alexandru Michis, Christian Holler reported memory safety bugs present in Thunderbird 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.


Please bump.
Comment 1 Larry the Git Cow gentoo-dev 2021-06-13 18:21:50 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1b33bd010bb2bafafa59f687284ce55430ce0cc8

commit 1b33bd010bb2bafafa59f687284ce55430ce0cc8
Author:     Thomas Deutschmann <whissi@gentoo.org>
AuthorDate: 2021-06-13 13:55:32 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2021-06-13 18:19:33 +0000

    mail-client/thunderbird-bin: security cleanup
    
    Bug: https://bugs.gentoo.org/794085
    Package-Manager: Portage-3.0.19, Repoman-3.0.3
    Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>

 mail-client/thunderbird-bin/Manifest               |  66 ----
 .../thunderbird-bin/thunderbird-bin-78.10.2.ebuild | 378 ---------------------
 2 files changed, 444 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=10fb5de39e4f33f808fe123374169f2e3af11361

commit 10fb5de39e4f33f808fe123374169f2e3af11361
Author:     Thomas Deutschmann <whissi@gentoo.org>
AuthorDate: 2021-06-13 13:54:55 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2021-06-13 18:19:33 +0000

    mail-client/thunderbird: security cleanup
    
    Bug: https://bugs.gentoo.org/794085
    Package-Manager: Portage-3.0.19, Repoman-3.0.3
    Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>

 mail-client/thunderbird/Manifest                   |   66 --
 mail-client/thunderbird/thunderbird-78.10.2.ebuild | 1108 --------------------
 2 files changed, 1174 deletions(-)
Comment 2 NATTkA bot gentoo-dev 2021-07-23 19:08:22 UTC Comment hidden (obsolete)
Comment 3 NATTkA bot gentoo-dev 2021-07-29 17:21:55 UTC Comment hidden (obsolete)
Comment 4 NATTkA bot gentoo-dev 2021-07-29 17:30:06 UTC Comment hidden (obsolete)
Comment 5 NATTkA bot gentoo-dev 2021-07-29 17:38:04 UTC Comment hidden (obsolete)
Comment 6 NATTkA bot gentoo-dev 2021-07-29 17:46:11 UTC Comment hidden (obsolete)
Comment 7 NATTkA bot gentoo-dev 2021-07-29 18:02:08 UTC Comment hidden (obsolete)
Comment 8 NATTkA bot gentoo-dev 2021-07-29 18:10:27 UTC
Package list is empty or all packages have requested keywords.
Comment 9 Larry the Git Cow gentoo-dev 2022-08-10 04:18:43 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=8856093f804feeda5fe9097d49ba3307aaefc9c2

commit 8856093f804feeda5fe9097d49ba3307aaefc9c2
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2022-08-10 04:08:55 +0000
Commit:     John Helmert III <ajak@gentoo.org>
CommitDate: 2022-08-10 04:17:36 +0000

    [ GLSA 202208-14 ] Mozilla Thunderbird: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/794085
    Bug: https://bugs.gentoo.org/802759
    Bug: https://bugs.gentoo.org/807943
    Bug: https://bugs.gentoo.org/811912
    Bug: https://bugs.gentoo.org/813501
    Bug: https://bugs.gentoo.org/822294
    Bug: https://bugs.gentoo.org/828539
    Bug: https://bugs.gentoo.org/831040
    Bug: https://bugs.gentoo.org/833520
    Bug: https://bugs.gentoo.org/834805
    Bug: https://bugs.gentoo.org/845057
    Bug: https://bugs.gentoo.org/846596
    Bug: https://bugs.gentoo.org/849047
    Bug: https://bugs.gentoo.org/857048
    Bug: https://bugs.gentoo.org/864577
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: John Helmert III <ajak@gentoo.org>

 glsa-202208-14.xml | 165 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 165 insertions(+)
Comment 10 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-10 04:26:44 UTC
GLSA released, all done!