An updated thunderbird package that fixes several security issues is nowavailable for Red Hat Enterprise Linux 5 and 6.The Red Hat Security Response Team has rated this update as havingImportant security impact. Common Vulnerability Scoring System (CVSS) basescores, which give detailed severity ratings, are available for eachvulnerability from the CVE links in the References section.

Mozilla Thunderbird is a standalone mail and newsgroup client.Several flaws were found in the processing of malformed web content. A webpage containing malicious content could cause Thunderbird to crash or,potentially, execute arbitrary code with the privileges of the user runningThunderbird. (CVE-2014-1533, CVE-2014-1538, CVE-2014-1541)Red Hat would like to thank the Mozilla project for reporting these issues.Upstream acknowledges Gary Kwong, Christoph Diehl, Christian Holler, HannesVerschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey,Abhishek Arya, and Nils as the original reporters of these issues.Note: All of the above issues cannot be exploited by a specially craftedHTML mail message as JavaScript is disabled by default for mail messages.They could be exploited another way in Thunderbird, for example, whenviewing the full remote content of an RSS feed.For technical details regarding these flaws, refer to the Mozilla securityadvisories for Thunderbird 24.6.0. You can find a link to the Mozillaadvisories in the References section of this erratum.All Thunderbird users should upgrade to this updated package, whichcontains Thunderbird version 24.6.0, which corrects these issues.After installing the update, Thunderbird must be restarted for the changesto take effect.
Before applying this update, make sure all previously released erratarelevant to your system have been applied.This update is available via the Red Hat Network. Details on how touse the Red Hat Network to apply this update are available athttps://access.redhat.com/site/articles/11258RHEL Optional Productivity Applications (v. 5 server)

SRPMS:
thunderbird-24.6.0-1.el5_10.src.rpm
    MD5: 670fc442638462ecb44a927bc372e792SHA-256: 097922d26a24f8b2130771d5aa64cd76a8b5161940ac5ef50ee6e2b9d8217c57
 
IA-32:
thunderbird-24.6.0-1.el5_10.i386.rpm
    MD5: 5dc0ded1a3586b31831c8a7e086beaabSHA-256: d7c8ad3543ea9a086fe1ea967c3e3d2a6787979e4f0d65489bb230b4e666a5d9
thunderbird-debuginfo-24.6.0-1.el5_10.i386.rpm
    MD5: 8d6b62bb1e52e52775053da8b19319bbSHA-256: 1bf59ef38c4accfac3a41f6cf7b7cd04f5bade84d4ff1162eab79eed6e85cd8f
 
x86_64:
thunderbird-24.6.0-1.el5_10.x86_64.rpm
    MD5: 97533d1d770a40bbb96815f84691398cSHA-256: 29d1f64946e80e33b12efd7b8529885448cb42f76920e5be6bee57847431aa69
thunderbird-debuginfo-24.6.0-1.el5_10.x86_64.rpm
    MD5: 062d77297a0ee16d99c18a0211c02365SHA-256: 470b98cff836612882b83d50591d47dca05eb12ae02bcb29ebf5507abc057fdc
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
thunderbird-24.6.0-1.el5_10.src.rpm
    MD5: 670fc442638462ecb44a927bc372e792SHA-256: 097922d26a24f8b2130771d5aa64cd76a8b5161940ac5ef50ee6e2b9d8217c57
 
IA-32:
thunderbird-24.6.0-1.el5_10.i386.rpm
    MD5: 5dc0ded1a3586b31831c8a7e086beaabSHA-256: d7c8ad3543ea9a086fe1ea967c3e3d2a6787979e4f0d65489bb230b4e666a5d9
thunderbird-debuginfo-24.6.0-1.el5_10.i386.rpm
    MD5: 8d6b62bb1e52e52775053da8b19319bbSHA-256: 1bf59ef38c4accfac3a41f6cf7b7cd04f5bade84d4ff1162eab79eed6e85cd8f
 
x86_64:
thunderbird-24.6.0-1.el5_10.x86_64.rpm
    MD5: 97533d1d770a40bbb96815f84691398cSHA-256: 29d1f64946e80e33b12efd7b8529885448cb42f76920e5be6bee57847431aa69
thunderbird-debuginfo-24.6.0-1.el5_10.x86_64.rpm
    MD5: 062d77297a0ee16d99c18a0211c02365SHA-256: 470b98cff836612882b83d50591d47dca05eb12ae02bcb29ebf5507abc057fdc
 
Red Hat Enterprise Linux Desktop (v. 6)

SRPMS:
thunderbird-24.6.0-1.el6_5.src.rpm
    MD5: 909c935d0e17754f748366bf38036ce2SHA-256: a1babe80f0b06acad2f79be631d4d78272f3c3d98a230bedd9cd3c1e48b4c537
 
IA-32:
thunderbird-24.6.0-1.el6_5.i686.rpm
    MD5: 3b819cf82692f870f5bf64a8177bb0e1SHA-256: 82a2d5ddb800ddfc6e3f27c2cc9c7441fb6180621776bddb8aa9b53c91ac9f29
thunderbird-debuginfo-24.6.0-1.el6_5.i686.rpm
    MD5: e631254828323cea6ce10a932e32fe78SHA-256: a2cf7634fd15bfc1afb8fa406ec32145ee67c0ca41dd8a897cfe6dc0368101c5
 
x86_64:
thunderbird-24.6.0-1.el6_5.x86_64.rpm
    MD5: cf15a61559d22a6d600a9f7a40ed09abSHA-256: 6e628b4fb63ce2ceace393e795548127e719ac0c3c30ff00d75759c0dfafc71b
thunderbird-debuginfo-24.6.0-1.el6_5.x86_64.rpm
    MD5: 3746d762677e205a09257d5abab3bec1SHA-256: 07b3f68c63c09584794c372002ab3b725bd851430feaf7c2d0d08a90ca84a361
 
Red Hat Enterprise Linux Server (v. 6)

SRPMS:
thunderbird-24.6.0-1.el6_5.src.rpm
    MD5: 909c935d0e17754f748366bf38036ce2SHA-256: a1babe80f0b06acad2f79be631d4d78272f3c3d98a230bedd9cd3c1e48b4c537
 
IA-32:
thunderbird-24.6.0-1.el6_5.i686.rpm
    MD5: 3b819cf82692f870f5bf64a8177bb0e1SHA-256: 82a2d5ddb800ddfc6e3f27c2cc9c7441fb6180621776bddb8aa9b53c91ac9f29
thunderbird-debuginfo-24.6.0-1.el6_5.i686.rpm
    MD5: e631254828323cea6ce10a932e32fe78SHA-256: a2cf7634fd15bfc1afb8fa406ec32145ee67c0ca41dd8a897cfe6dc0368101c5
 
PPC:
thunderbird-24.6.0-1.el6_5.ppc64.rpm
    MD5: d759430351fe04dd8f93ff2ca520607bSHA-256: 4c08006b862254c2c5ea02394faf9aa41fc1fb55a7db2697c746973f37026da6
thunderbird-debuginfo-24.6.0-1.el6_5.ppc64.rpm
    MD5: 48d4def869a63f0b3c77afd488887943SHA-256: 6d2a78d25dc23e027f3fbce4cbf5ef9ab94d2f4ef7f253d57a82b037b94bc3c2
 
s390x:
thunderbird-24.6.0-1.el6_5.s390x.rpm
    MD5: b9b429c6999a86db7f917efbea4d30a4SHA-256: 335ad40669d65fa266b7c892f1053de81b9860c14186a1c5190130eebd3a30bb
thunderbird-debuginfo-24.6.0-1.el6_5.s390x.rpm
    MD5: 6af87b51def217aa838cee6b84c5c48bSHA-256: b6848f829962c06d42539da993ee207d290cc15bb67cbf97adf60b16d4b8453f
 
x86_64:
thunderbird-24.6.0-1.el6_5.x86_64.rpm
    MD5: cf15a61559d22a6d600a9f7a40ed09abSHA-256: 6e628b4fb63ce2ceace393e795548127e719ac0c3c30ff00d75759c0dfafc71b
thunderbird-debuginfo-24.6.0-1.el6_5.x86_64.rpm
    MD5: 3746d762677e205a09257d5abab3bec1SHA-256: 07b3f68c63c09584794c372002ab3b725bd851430feaf7c2d0d08a90ca84a361
 
Red Hat Enterprise Linux Server AUS (v. 6.5)

SRPMS:
thunderbird-24.6.0-1.el6_5.src.rpm
    MD5: 909c935d0e17754f748366bf38036ce2SHA-256: a1babe80f0b06acad2f79be631d4d78272f3c3d98a230bedd9cd3c1e48b4c537
 
x86_64:
thunderbird-24.6.0-1.el6_5.x86_64.rpm
    MD5: cf15a61559d22a6d600a9f7a40ed09abSHA-256: 6e628b4fb63ce2ceace393e795548127e719ac0c3c30ff00d75759c0dfafc71b
thunderbird-debuginfo-24.6.0-1.el6_5.x86_64.rpm
    MD5: 3746d762677e205a09257d5abab3bec1SHA-256: 07b3f68c63c09584794c372002ab3b725bd851430feaf7c2d0d08a90ca84a361
 
Red Hat Enterprise Linux Server EUS (v. 6.5.z)

SRPMS:
thunderbird-24.6.0-1.el6_5.src.rpm
    MD5: 909c935d0e17754f748366bf38036ce2SHA-256: a1babe80f0b06acad2f79be631d4d78272f3c3d98a230bedd9cd3c1e48b4c537
 
IA-32:
thunderbird-24.6.0-1.el6_5.i686.rpm
    MD5: 3b819cf82692f870f5bf64a8177bb0e1SHA-256: 82a2d5ddb800ddfc6e3f27c2cc9c7441fb6180621776bddb8aa9b53c91ac9f29
thunderbird-debuginfo-24.6.0-1.el6_5.i686.rpm
    MD5: e631254828323cea6ce10a932e32fe78SHA-256: a2cf7634fd15bfc1afb8fa406ec32145ee67c0ca41dd8a897cfe6dc0368101c5
 
PPC:
thunderbird-24.6.0-1.el6_5.ppc64.rpm
    MD5: d759430351fe04dd8f93ff2ca520607bSHA-256: 4c08006b862254c2c5ea02394faf9aa41fc1fb55a7db2697c746973f37026da6
thunderbird-debuginfo-24.6.0-1.el6_5.ppc64.rpm
    MD5: 48d4def869a63f0b3c77afd488887943SHA-256: 6d2a78d25dc23e027f3fbce4cbf5ef9ab94d2f4ef7f253d57a82b037b94bc3c2
 
s390x:
thunderbird-24.6.0-1.el6_5.s390x.rpm
    MD5: b9b429c6999a86db7f917efbea4d30a4SHA-256: 335ad40669d65fa266b7c892f1053de81b9860c14186a1c5190130eebd3a30bb
thunderbird-debuginfo-24.6.0-1.el6_5.s390x.rpm
    MD5: 6af87b51def217aa838cee6b84c5c48bSHA-256: b6848f829962c06d42539da993ee207d290cc15bb67cbf97adf60b16d4b8453f
 
x86_64:
thunderbird-24.6.0-1.el6_5.x86_64.rpm
    MD5: cf15a61559d22a6d600a9f7a40ed09abSHA-256: 6e628b4fb63ce2ceace393e795548127e719ac0c3c30ff00d75759c0dfafc71b
thunderbird-debuginfo-24.6.0-1.el6_5.x86_64.rpm
    MD5: 3746d762677e205a09257d5abab3bec1SHA-256: 07b3f68c63c09584794c372002ab3b725bd851430feaf7c2d0d08a90ca84a361
 
Red Hat Enterprise Linux Workstation (v. 6)

SRPMS:
thunderbird-24.6.0-1.el6_5.src.rpm
    MD5: 909c935d0e17754f748366bf38036ce2SHA-256: a1babe80f0b06acad2f79be631d4d78272f3c3d98a230bedd9cd3c1e48b4c537
 
IA-32:
thunderbird-24.6.0-1.el6_5.i686.rpm
    MD5: 3b819cf82692f870f5bf64a8177bb0e1SHA-256: 82a2d5ddb800ddfc6e3f27c2cc9c7441fb6180621776bddb8aa9b53c91ac9f29
thunderbird-debuginfo-24.6.0-1.el6_5.i686.rpm
    MD5: e631254828323cea6ce10a932e32fe78SHA-256: a2cf7634fd15bfc1afb8fa406ec32145ee67c0ca41dd8a897cfe6dc0368101c5
 
x86_64:
thunderbird-24.6.0-1.el6_5.x86_64.rpm
    MD5: cf15a61559d22a6d600a9f7a40ed09abSHA-256: 6e628b4fb63ce2ceace393e795548127e719ac0c3c30ff00d75759c0dfafc71b
thunderbird-debuginfo-24.6.0-1.el6_5.x86_64.rpm
    MD5: 3746d762677e205a09257d5abab3bec1SHA-256: 07b3f68c63c09584794c372002ab3b725bd851430feaf7c2d0d08a90ca84a361
 
(The unlinked packages above are only available from the Red Hat Network)
1107399 – CVE-2014-1533 Mozilla: Miscellaneous memory safety hazards (rv:24.6) (MFSA 2014-48)1107421 – CVE-2014-1538 Mozilla: Use-after-free and out of bounds issues found using Address Sanitizer (MFSA 2014-49)1107424 – CVE-2014-1541 Mozilla: Use-after-free with SMIL Animation Controller (MFSA 2014-52)

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from:

Leave a Reply