Gentoo Archives: gentoo-announce

From: Aaron Bauman <bman@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202102-02 ] Mozilla Thunderbird: Multiple vulnerabilities
Date: Mon, 01 Feb 2021 02:00:13
Message-Id: YBdcyPUrjj1fs4MC@samurai
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202102-02
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Mozilla Thunderbird: Multiple vulnerabilities
9 Date: February 01, 2021
10 Bugs: #767394
11 ID: 202102-02
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Mozilla Thunderbird, the
19 worst of which could result in the arbitrary execution of code.
20
21 Background
22 ==========
23
24 Mozilla Thunderbird is a popular open-source email client from the
25 Mozilla project.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 mail-client/thunderbird < 78.7.0 >= 78.7.0
34 2 mail-client/thunderbird-bin
35 < 78.7.0 >= 78.7.0
36 -------------------------------------------------------------------
37 2 affected packages
38
39 Description
40 ===========
41
42 Multiple vulnerabilities have been discovered in Mozilla Thunderbird.
43 Please review the CVE identifiers referenced below for details.
44
45 Impact
46 ======
47
48 Please review the referenced CVE identifiers for details.
49
50 Workaround
51 ==========
52
53 There is no known workaround at this time.
54
55 Resolution
56 ==========
57
58 All Mozilla Thunderbird users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=mail-client/thunderbird-78.7.0"
62
63 All Mozilla Thunderbird binary users should upgrade to the latest
64 version:
65
66 # emerge --sync
67 # emerge --ask --oneshot -v ">=mail-client/thunderbird-bin-78.7.0"
68
69 References
70 ==========
71
72 [ 1 ] CVE-2020-15685
73 https://nvd.nist.gov/vuln/detail/CVE-2020-15685
74 [ 2 ] CVE-2020-26976
75 https://nvd.nist.gov/vuln/detail/CVE-2020-26976
76 [ 3 ] CVE-2021-23953
77 https://nvd.nist.gov/vuln/detail/CVE-2021-23953
78 [ 4 ] CVE-2021-23954
79 https://nvd.nist.gov/vuln/detail/CVE-2021-23954
80 [ 5 ] CVE-2021-23960
81 https://nvd.nist.gov/vuln/detail/CVE-2021-23960
82 [ 6 ] CVE-2021-23964
83 https://nvd.nist.gov/vuln/detail/CVE-2021-23964
84 [ 7 ] Upstream advisory (MFSA-2021-05)
85 https://www.mozilla.org/en-US/security/advisories/mfsa2021-05/
86
87 Availability
88 ============
89
90 This GLSA and any updates to it are available for viewing at
91 the Gentoo Security Website:
92
93 https://security.gentoo.org/glsa/202102-02
94
95 Concerns?
96 =========
97
98 Security is a primary focus of Gentoo Linux and ensuring the
99 confidentiality and security of our users' machines is of utmost
100 importance to us. Any security concerns should be addressed to
101 security@g.o or alternatively, you may file a bug at
102 https://bugs.gentoo.org.
103
104 License
105 =======
106
107 Copyright 2021 Gentoo Foundation, Inc; referenced text
108 belongs to its owner(s).
109
110 The contents of this document are licensed under the
111 Creative Commons - Attribution / Share Alike license.
112
113 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature