MGASA-2021-0584

Source
https://advisories.mageia.org/MGASA-2021-0584.html
Import Source
https://advisories.mageia.org/MGASA-2021-0584.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0584
Related
Published
2021-12-23T21:01:45Z
Modified
2021-12-23T20:23:16Z
Summary
Updated thunderbird packages fix security vulnerability
Details

OpenPGP signature status doesn't consider additional message content. (CVE-2021-4126)

Matrix chat library libolm bundled with Thunderbird vulnerable to a buffer overflow. (CVE-2021-44538)

References
Credits

Affected packages

Mageia:8 / thunderbird

Package

Name
thunderbird
Purl
pkg:rpm/mageia/thunderbird?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
91.4.1-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / thunderbird-l10n

Package

Name
thunderbird-l10n
Purl
pkg:rpm/mageia/thunderbird-l10n?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
91.4.1-1.mga8

Ecosystem specific

{
    "section": "core"
}