Mozilla Thunderbird 115.3.1 download the new version

broken image

#CVE-2023-4049: Fix potential race conditions when releasing platform objects Reporter Nika Layzell Impact high Description #CVE-2023-4048: Crash in DOMParser due to out-of-memory conditions Reporter Irvan Kurniawan Impact high DescriptionĪn out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. #CVE-2023-4047: Potential permissions request bypass via clickjacking Reporter Axel Chong Impact high DescriptionĪ bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This resulted in incorrect compilation and a potentially exploitable crash in the content process. In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis.

broken image
broken image

#CVE-2023-4046: Incorrect value used during WASM compilation Reporter Alexander Guryanov Impact high Description Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy.

broken image

#CVE-2023-4045: Offscreen Canvas could have bypassed cross-origin restrictions Reporter Max Vlasov Impact high Description

Mozilla Foundation Security Advisory 2023-31 Security Vulnerabilities fixed in Firefox ESR 115.1 Announced AugImpact high Products Firefox ESR Fixed in

broken image