Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 941175 - <mail-client/thunderbird{-bin,}-{115.15.0,128.2.0}: Multiple vulnerabilities
Summary: <mail-client/thunderbird{-bin,}-{115.15.0,128.2.0}: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://www.mozilla.org/en-US/securit...
Whiteboard: A3 [glsa+]
Keywords:
Depends on:
Blocks: CVE-2024-8381, CVE-2024-8382, CVE-2024-8383, CVE-2024-8384, CVE-2024-8385, CVE-2024-8386, CVE-2024-8387, CVE-2024-8389, CVE-2024-8394, MFSA2024-39, MFSA2024-40, MFSA2024-41, MFSA2024-43, MFSA2024-44
  Show dependency tree
 
Reported: 2024-10-08 19:07 UTC by Christopher Fore
Modified: 2024-12-07 10:34 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Christopher Fore 2024-10-08 19:07:38 UTC
**The following CVE(s) only affect Thunderbird 128.2.x**

CVE-2024-8394:

When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash.



Please refer to the tracker for the full list of CVEs that affect all Mozilla products.
Comment 1 Joonas Niilola gentoo-dev 2024-10-09 07:14:02 UTC
Tree is clean for these versions.
Comment 2 Larry the Git Cow gentoo-dev 2024-12-07 10:32:33 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=0218a1fa61b66d9f084e38fe4f79e7ce3b62ba26

commit 0218a1fa61b66d9f084e38fe4f79e7ce3b62ba26
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2024-12-07 10:32:19 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2024-12-07 10:32:30 +0000

    [ GLSA 202412-06 ] Mozilla Thunderbird: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/935551
    Bug: https://bugs.gentoo.org/936216
    Bug: https://bugs.gentoo.org/937468
    Bug: https://bugs.gentoo.org/941170
    Bug: https://bugs.gentoo.org/941175
    Bug: https://bugs.gentoo.org/942470
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202412-06.xml | 133 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 133 insertions(+)