Bug 8639 - [Anolis OS 8] Bugfix for CVE-2024-1936
Summary: [Anolis OS 8] Bugfix for CVE-2024-1936
Status: NEW
Alias: None
Product: Anolis OS 8
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: 8.6
Hardware: All Linux
: P2-High S2-major
Target Milestone: ---
Assignee: songkai
QA Contact: shuming
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2024-03-26 10:29 UTC by 小龙
Modified: 2024-03-27 10:23 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2024-03-26 10:29:23 UTC
Description:
The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird < 115.8.1.

Broken commit info:

Bugfix commit info:
https://bugzilla.mozilla.org/attachment.cgi?id=9382153
https://bugzilla.mozilla.org/attachment.cgi?id=9381948