RHSA-2021:3841HighCVSS 9.8
Red Hat Security Advisory: thunderbird security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2021-32810 — rust-crossbeam-deque: race condition may lead to double free CVE-2021-38496 — Mozilla: Use-after-free in MessageTask CVE-2021-38497 — Mozilla: Validation message could have been overlaid on another origin CVE-2021-38498 — Mozilla: Use-after-free of nsLanguageAtomService object CVE-2021-38500 — Mozilla: Memory safety bugs fixed in Firefox 93, Firefox ESR 78.15, and Firefox ESR 91.2 CVE-2021-38501 — Mozilla: Memory safety bugs fixed in Firefox 93 and Firefox ESR 91.2 CVE-2021-38502 — Mozilla: Downgrade attack on SMTP STARTTLS connections
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2021:3841
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1990342
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011097
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011098
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011099
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011100
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011101
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2013469
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3841.json