Red Hat Security Advisory: thunderbird security update
Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): * firefox: thunderbird: History interface could have been used to cause a Denial of Service condition in the browser (CVE-2024-10464) * firefox: thunderbird: XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response (CVE-2024-10461) * firefox: thunderbird: Permission leak via embed or object elements (CVE-2024-10458) * firefox: thunderbird: Use-after-free in layout with accessibility (CVE-2024-10459) * firefox: thunderbird: Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4 (CVE-2024-10467) * firefox: thunderbird: Clipboard "paste" button persisted across tabs (CVE-2024-10465) * firefox: DOM push subscription message could hang Firefox (CVE-2024-10466) * firefox: thunderbird: Cross origin video frame leak (CVE-2024-10463) * firefox: thunderbird: Origin of permission prompt could be spoofed by long URL (CVE-2024-10462) * firefox: thunderbird: Confusing display of origin for external protocol handler prompt (CVE-2024-10460) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
This Red Hat security advisory addresses a set of vulnerabilities in Mozilla Thunderbird, including CVE-2024-10458 and nine other related CVEs. The issues range from permission leaks via embed or object elements, use-after-free bugs in layout accessibility, XSS vulnerabilities due to improper handling of Content-Disposition headers, denial of service via the history interface, cross-origin video frame leaks, spoofing of permission prompt origins, and memory safety bugs. These vulnerabilities have been fixed in Thunderbird 128.4 and Firefox 132 releases. The advisory applies to Red Hat Enterprise Linux 8.2 and provides updated Thunderbird packages to mitigate these risks.
Potential Impact
The vulnerabilities collectively could allow attackers to cause denial of service conditions, execute cross-site scripting attacks, leak permissions, exploit use-after-free memory errors, and spoof UI elements related to permission prompts. These issues could affect the confidentiality, integrity, and availability of the Thunderbird client and potentially impact user security and privacy. The security impact is rated as Moderate by Red Hat.
Mitigation Recommendations
Red Hat has released updated Thunderbird packages for Red Hat Enterprise Linux 8.2 (Thunderbird 128.4) that address these vulnerabilities. Users should apply the security update as described in Red Hat advisory RHSA-2024:9016 and the related article https://access.redhat.com/articles/11258 to remediate these issues. No additional mitigation steps are indicated beyond applying the official update.
Red Hat Security Advisory: thunderbird security update
Description
Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): * firefox: thunderbird: History interface could have been used to cause a Denial of Service condition in the browser (CVE-2024-10464) * firefox: thunderbird: XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response (CVE-2024-10461) * firefox: thunderbird: Permission leak via embed or object elements (CVE-2024-10458) * firefox: thunderbird: Use-after-free in layout with accessibility (CVE-2024-10459) * firefox: thunderbird: Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4 (CVE-2024-10467) * firefox: thunderbird: Clipboard "paste" button persisted across tabs (CVE-2024-10465) * firefox: DOM push subscription message could hang Firefox (CVE-2024-10466) * firefox: thunderbird: Cross origin video frame leak (CVE-2024-10463) * firefox: thunderbird: Origin of permission prompt could be spoofed by long URL (CVE-2024-10462) * firefox: thunderbird: Confusing display of origin for external protocol handler prompt (CVE-2024-10460) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory addresses a set of vulnerabilities in Mozilla Thunderbird, including CVE-2024-10458 and nine other related CVEs. The issues range from permission leaks via embed or object elements, use-after-free bugs in layout accessibility, XSS vulnerabilities due to improper handling of Content-Disposition headers, denial of service via the history interface, cross-origin video frame leaks, spoofing of permission prompt origins, and memory safety bugs. These vulnerabilities have been fixed in Thunderbird 128.4 and Firefox 132 releases. The advisory applies to Red Hat Enterprise Linux 8.2 and provides updated Thunderbird packages to mitigate these risks.
Potential Impact
The vulnerabilities collectively could allow attackers to cause denial of service conditions, execute cross-site scripting attacks, leak permissions, exploit use-after-free memory errors, and spoof UI elements related to permission prompts. These issues could affect the confidentiality, integrity, and availability of the Thunderbird client and potentially impact user security and privacy. The security impact is rated as Moderate by Red Hat.
Mitigation Recommendations
Red Hat has released updated Thunderbird packages for Red Hat Enterprise Linux 8.2 (Thunderbird 128.4) that address these vulnerabilities. Users should apply the security update as described in Red Hat advisory RHSA-2024:9016 and the related article https://access.redhat.com/articles/11258 to remediate these issues. No additional mitigation steps are indicated beyond applying the official update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2024:9016
- Cve Count
- 10
- Additional Cves
- ["CVE-2024-10459","CVE-2024-10460","CVE-2024-10461","CVE-2024-10462","CVE-2024-10463","CVE-2024-10464","CVE-2024-10465","CVE-2024-10466","CVE-2024-10467"]
Threat ID: 6a3e8058cef61ccff96ffa2c
Added to database: 06/26/2026, 13:36:24 UTC
Last enriched: 06/26/2026, 13:38:00 UTC
Last updated: 09/10/2026, 19:36:47 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.