This commit is contained in:
Tom Ritter 2024-09-06 12:15:33 -04:00
Родитель 1c7adcc6be
Коммит a6bcdbdbab
1 изменённых файлов: 8 добавлений и 0 удалений

Просмотреть файл

@ -7,6 +7,14 @@ title: Security Vulnerabilities fixed in Thunderbird 128.2
description: |
*In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potential risks in browser or browser-like contexts.*
advisories:
CVE-2024-8394:
title: Crash when aborting verification of OTR chat
impact: high
reporter: Thunderbird Team
description: |
When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash.
bugs:
- url: 1895737
CVE-2024-8385:
title: WASM type confusion involving ArrayTypes
impact: high