AlmaLinux 2239 Published by

A thunderbird security update has been released for Alma Linux 8.3.



ALSA-2021:1193 Moderate: thunderbird security update


Type:
security
Severity:
moderate
Release date:
2021-04-14
Description
This update upgrades Thunderbird to version 78.9.1.
Security Fix(es):
* Mozilla: An attacker may use Thunderbird's OpenPGP key refresh mechanism to poison an existing key (CVE-2021-23991)
* Mozilla: A crafted OpenPGP key with an invalid user ID could be used to confuse the user (CVE-2021-23992)
* Mozilla: Inability to send encrypted OpenPGP email after importing a crafted OpenPGP key (CVE-2021-23993)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References:
CVE-2021-23991
CVE-2021-23992
CVE-2021-23993
CVE-2021-29949
CVE-2021-29950
Updates packages:
thunderbird-78.9.1-1.el8_3.alma.x86_64.rpm
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

  ALSA-2021:1193 Moderate: thunderbird security update