VDB

GCVE-110-MAGEIA-2024-6

GCVE-110-MAGEIA-2024-6
Advisory Published
Vulnetix · Advisory published January 12, 2024
The updated packages fix security vulnerabilities: Truncated signed text was shown with a valid OpenPGP signature. (CVE-2023-50762) S/MIME signature accepted despite mismatching message date. (CVE-2023-50761) Heap-buffer-overflow affecting WebGL DrawElementsInstanced method with Mesa VM driver. (CVE-2023-6856) Symlinks may resolve to smaller than expected buffers. (CVE-2023-6857) Heap buffer overflow in nsTextFragment. (CVE-2023-6858) Use-after-free in PR_GetIdentitiesLayer. (CVE-2023-6859) Potential sandbox escape due to VideoBridge lack of texture validation. (CVE-2023-6860) Heap buffer overflow affected nsWindow::PickerOpen(void) in headless mode. (CVE-2023-6861) Use-after-free in nsDNSService. (CVE-2023-6862) Undefined behavior in ShutdownObserver(). (CVE-2023-6863) Memory safety bugs fixed in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. (CVE-2023-6864)

Affected Products

VendorProductVersionsPlatforms
Mageiapython-pyglet0 (affected), 1.5.27-1.mga9 (unaffected)
Mageiathunderbird0 (affected), 115.6.0-1.mga9 (unaffected), 0 (affected), 115.6.0-1.mga9 (unaffected)
Mageiathunderbird-l10n0 (affected), 115.6.0-1.mga9 (unaffected), 0 (affected), 115.6.0-1.mga9 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›