Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.884242
Kategorie:CentOS Local Security Checks
Titel:CentOS: Security Advisory for thunderbird (CESA-2022:6169)
Zusammenfassung:The remote host is missing an update for the 'thunderbird'; package(s) announced via the CESA-2022:6169 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'thunderbird'
package(s) announced via the CESA-2022:6169 advisory.

Vulnerability Insight:
Mozilla Thunderbird is a standalone mail and newsgroup client.

This update upgrades Thunderbird to version 91.13.0.

Security Fix(es):

* Mozilla: Address bar spoofing via XSLT error handling (CVE-2022-38472)

* Mozilla: Cross-origin XSLT Documents would have inherited the parent's
permissions (CVE-2022-38473)

* Mozilla: Memory safety bugs fixed in Firefox 104 and Firefox ESR 102.2
(CVE-2022-38477)

* Mozilla: Memory safety bugs fixed in Firefox 104, Firefox ESR 102.2, and
Firefox ESR 91.13 (CVE-2022-38478)

* Mozilla: Data race and potential use-after-free in PK11_ChangePW
(CVE-2022-38476)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Affected Software/OS:
'thunderbird' package(s) on CentOS 7.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2022-38472
https://bugzilla.mozilla.org/show_bug.cgi?id=1769155
https://www.mozilla.org/security/advisories/mfsa2022-33/
https://www.mozilla.org/security/advisories/mfsa2022-34/
https://www.mozilla.org/security/advisories/mfsa2022-35/
https://www.mozilla.org/security/advisories/mfsa2022-36/
https://www.mozilla.org/security/advisories/mfsa2022-37/
Common Vulnerability Exposure (CVE) ID: CVE-2022-38473
https://bugzilla.mozilla.org/show_bug.cgi?id=1771685
Common Vulnerability Exposure (CVE) ID: CVE-2022-38476
https://bugzilla.mozilla.org/show_bug.cgi?id=1760998
Common Vulnerability Exposure (CVE) ID: CVE-2022-38477
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1760611%2C1770219%2C1771159%2C1773363
Common Vulnerability Exposure (CVE) ID: CVE-2022-38478
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1770630%2C1776658
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.