Rocky Linux 8 [CIQ] 安全性更新:thunderbird / thunderbird-debuginfo / thunderbird-debugsource 多個弱點 (crlsa-2023_4954)

high Nessus Plugin ID 354848

概要

Rocky Linux 主機缺少一或多個安全性更新。

說明

Rocky Linux 8 主機已安裝的套件會受到 CIQ crlsa-2023_4954 公告中提及的多個弱點影響。

* Mozilla:IPC CanvasTranslator (CVE-2023-4573) 中的記憶體損毀

* Mozilla:IPC ColorPickerShownCallback 中的記憶體損毀 (CVE-2023-4574)

* Mozilla:IPC FilePickerShownCallback (CVE-2023-4575) 中的記憶體損毀

* Mozilla:JIT UpdateRegExpStatics (CVE-2023-4577) 中的記憶體損毀

* Mozilla:在 Firefox 117、Firefox ESR 102.15、Firefox ESR 115.2、Thunderbird 102.15和 Thunderbird 115.2 (CVE-2023-4584) 中修正了記憶體安全錯誤

* Mozilla:在 Firefox 117、Firefox ESR 115.2和 Thunderbird 115.2 中修正了記憶體安全錯誤 (CVE-2023-4585)

* Mozilla:全螢幕通知被檔案開啟對話方塊 (CVE-2023-4051) 遮擋

* Mozilla:被外部程式 (CVE-2023-4053) 遮擋的全螢幕通知

* Mozilla:SpiderMonkey 中的錯誤報告方法可觸發記憶體不足例外狀況 (CVE-2023-4578)

* Mozilla:推送通知以未加密的方式儲存至磁碟 (CVE-2023-4580)

* Mozilla:可在沒有警告的情況下下載 XLL 副檔名 (CVE-2023-4581)

* Mozilla:關閉私人視窗時,瀏覽上下文可能未清除 (CVE-2023-4583)

Tenable 已直接從 CIQ 安全性公告中擷取上述描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 CIQ 公告 crlsa-2023_4954中的指引更新受影響的套件。

另請參閱

https://access.redhat.com/errata/RHSA-2023:4954

https://bugzilla.redhat.com/show_bug.cgi?id=2236071

https://bugzilla.redhat.com/show_bug.cgi?id=2236072

https://bugzilla.redhat.com/show_bug.cgi?id=2236073

https://bugzilla.redhat.com/show_bug.cgi?id=2236075

https://bugzilla.redhat.com/show_bug.cgi?id=2236076

https://bugzilla.redhat.com/show_bug.cgi?id=2236077

https://bugzilla.redhat.com/show_bug.cgi?id=2236078

https://bugzilla.redhat.com/show_bug.cgi?id=2236079

https://bugzilla.redhat.com/show_bug.cgi?id=2236080

https://bugzilla.redhat.com/show_bug.cgi?id=2236082

https://bugzilla.redhat.com/show_bug.cgi?id=2236084

https://bugzilla.redhat.com/show_bug.cgi?id=2236086

https://errata.build.resf.org/RLSA-2023:4954

http://www.nessus.org/u?aa289dae

http://www.nessus.org/u?cba2b63e

Plugin 詳細資訊

嚴重性: High

ID: 354848

檔案名稱: ciq_rocky_linux_8_crlsa-2023_4954.nasl

版本: 1.1

類型: Local

已發布: 2026/10/1

已更新: 2026/10/1

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Medium

分數: 4.9

百分位數: 57.58

Vendor

Vendor Severity: Unknown

CVSS v2

風險因素: Critical

基本分數: 10

時間性分數: 7.4

媒介: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2023-4585

CVSS v3

風險因素: High

基本分數: 8.8

時間性分數: 7.7

媒介: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:U/RL:O/RC:C

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/cpu

可輕鬆利用: No known exploits are available

修補程式發佈日期: 2023/10/6

弱點發布日期: 2023/8/1

參考資訊

CVE: CVE-2023-4051, CVE-2023-4053, CVE-2023-4573, CVE-2023-4574, CVE-2023-4575, CVE-2023-4577, CVE-2023-4578, CVE-2023-4580, CVE-2023-4581, CVE-2023-4583, CVE-2023-4584, CVE-2023-4585