Multiple security issues were discovered in Thunderbird. If a user were tricked into opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass security restrictions, cross-site tracing, or execute arbitrary code.(CVE-2024-5688, CVE-2024-5690, CVE-2024-5696, CVE-2024-5700, CVE-2024-5702)
Luan Herrera discovered that Thunderbird did not properly validate the X-Frame-Options header inside sandboxed iframe. An attacker could potentially exploit this issue to bypass sandbox restrictions to open a new window. (CVE-2024-5691)
Kirtikumar Anandrao Ramchandani discovered that Thunderbird did not properly track cross-origin tainting in Offscreen Canvas. An attacker could potentially exploit this issue to access image data from another site in violation of same-origin policy. (CVE-2024-5693)
{ "binaries": [ { "binary_name": "thunderbird", "binary_version": "1:115.12.0+build3-0ubuntu0.20.04.1" }, { "binary_name": "thunderbird-dev", "binary_version": "1:115.12.0+build3-0ubuntu0.20.04.1" }, { "binary_name": "thunderbird-gnome-support", "binary_version": "1:115.12.0+build3-0ubuntu0.20.04.1" }, { "binary_name": "thunderbird-mozsymbols", "binary_version": "1:115.12.0+build3-0ubuntu0.20.04.1" }, { "binary_name": "xul-ext-calendar-timezones", "binary_version": "1:115.12.0+build3-0ubuntu0.20.04.1" }, { "binary_name": "xul-ext-gdata-provider", "binary_version": "1:115.12.0+build3-0ubuntu0.20.04.1" }, { "binary_name": "xul-ext-lightning", "binary_version": "1:115.12.0+build3-0ubuntu0.20.04.1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "thunderbird", "binary_version": "1:115.12.0+build3-0ubuntu0.22.04.1" }, { "binary_name": "thunderbird-dev", "binary_version": "1:115.12.0+build3-0ubuntu0.22.04.1" }, { "binary_name": "thunderbird-gnome-support", "binary_version": "1:115.12.0+build3-0ubuntu0.22.04.1" }, { "binary_name": "thunderbird-mozsymbols", "binary_version": "1:115.12.0+build3-0ubuntu0.22.04.1" }, { "binary_name": "xul-ext-calendar-timezones", "binary_version": "1:115.12.0+build3-0ubuntu0.22.04.1" }, { "binary_name": "xul-ext-gdata-provider", "binary_version": "1:115.12.0+build3-0ubuntu0.22.04.1" }, { "binary_name": "xul-ext-lightning", "binary_version": "1:115.12.0+build3-0ubuntu0.22.04.1" } ], "availability": "No subscription required" }