AlmaLinux 9.2 [TuxCare] 安全更新:thunderbird 多个漏洞 (ALMALINUX9.2:CLSA-2026:1785560172)

critical Nessus 插件 ID 360088

简介

AlmaLinux 主机缺少一个或多个安全更新。

描述

AlmaLinux 9.2 主机上存在安装的程序包,该程序包受到 TuxCare ALMALINUX9.2:CLSA-2026:2026:1785560172公告中提及的多个漏洞的影响。

- 验证 S/Mime 签名时未检查证书 OCSP 吊销状态。使用已撤消的证书签名的邮件将显示为具有有效签名。Thunderbird 68 至 102.7.0 版受到此错误影响。此漏洞会影响 Thunderbird < 102.7.1。(CVE-2023-0430)

- 如果 MIME 电子邮件以某种方式结合使用 OpenPGP 和 OpenPGP MIME 数据,Thunderbird 会反复尝试处理和显示消息,从而导致 Thunderbird 的用户界面锁定并且不再响应用户的操作。攻击者可发送具有此结构的构建消息,以尝试发起 DoS 攻击。此漏洞会影响 Thunderbird < 102.8。(CVE-2023-0616)

从安全浏览 API 返回的意外数据可能导致内存损坏和潜在的可利用崩溃。此漏洞会影响 Thunderbird < 102.10 和 Firefox ESR < 102.10。
(CVE-2023-1945)

- 由于 Firefox GTK 封装程序代码对拖动数据使用 text/plain,并且 GTK 将包含文件 URL 的所有 text/plain MIME 视为正在拖动,因此网站可通过对“DataTransfer.setData”的调用任意读取文件。该漏洞影响 Firefox < 109、Firefox ESR < 102.7和 Thunderbird < 102.7。(CVE-2023-23598)

- 将 SPKI RSA 公钥导入为 ECDSA P-256 时,可能未正确处理密钥,导致选项卡崩溃。此漏洞会影响 Firefox < 110、Thunderbird < 102.8 和 Firefox ESR < 102.8。
(CVE-2023-25742)

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 TuxCare 公告 ALMALINUX9.2:CLSA-2026:1785560172 中的指南更新受影响的 thunderbird 程序包。

另见

https://cve.tuxcare.com/els/releases/CLSA-2026:1785560172

http://www.nessus.org/u?89e6800e

插件详情

严重性: Critical

ID: 360088

文件名: tuxcare_alma_linux_9.2_CLSA-2026-1785560172.nasl

版本: 1.1

类型: Local

发布时间: 2026/10/1

最近更新时间: 2026/10/1

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.6

百分位: 98.37

Vendor

Vendor Severity: Critical

CVSS v2

风险因素: Critical

基本分数: 10

时间分数: 7.8

矢量: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-4710

CVSS v3

风险因素: Critical

基本分数: 10

时间分数: 9

矢量: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

CVSS 分数来源: CVE-2026-4692

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/8/1

漏洞发布日期: 2022/8/31

参考资料信息

CVE: CVE-2022-3032, CVE-2023-0430, CVE-2023-0547, CVE-2023-0616, CVE-2023-1945, CVE-2023-23598, CVE-2023-23599, CVE-2023-23601, CVE-2023-23602, CVE-2023-25728, CVE-2023-25730, CVE-2023-25737, CVE-2023-25742, CVE-2023-25751, CVE-2023-25752, CVE-2023-28164, CVE-2023-29533, CVE-2023-29535, CVE-2023-29536, CVE-2023-29539, CVE-2023-29548, CVE-2023-32206, CVE-2023-32211, CVE-2023-37207, CVE-2023-4573, CVE-2023-4574, CVE-2023-4575, CVE-2023-4577, CVE-2023-4578, CVE-2023-4580, CVE-2023-4581, CVE-2023-50761, CVE-2023-50762, CVE-2023-5169, CVE-2023-5171, CVE-2023-5724, CVE-2023-5725, CVE-2023-5732, CVE-2023-6204, CVE-2023-6205, CVE-2023-6206, CVE-2023-6207, CVE-2023-6208, CVE-2023-6209, CVE-2023-6212, CVE-2023-6856, CVE-2023-6857, CVE-2023-6859, CVE-2023-6860, CVE-2023-6862, CVE-2023-6863, CVE-2023-6864, CVE-2024-0746, CVE-2024-0750, CVE-2024-0751, CVE-2024-10458, CVE-2024-10459, CVE-2024-10460, CVE-2024-10461, CVE-2024-10462, CVE-2024-10463, CVE-2024-10464, CVE-2024-10465, CVE-2024-10466, CVE-2024-10467, CVE-2024-10468, CVE-2024-11159, CVE-2024-11692, CVE-2024-11693, CVE-2024-11694, CVE-2024-11695, CVE-2024-11696, CVE-2024-11697, CVE-2024-11700, CVE-2024-11701, CVE-2024-11702, CVE-2024-11704, CVE-2024-11705, CVE-2024-11706, CVE-2024-11708, CVE-2024-1546, CVE-2024-1547, CVE-2024-1548, CVE-2024-1549, CVE-2024-1550, CVE-2024-1551, CVE-2024-1553, CVE-2024-2608, CVE-2024-2609, CVE-2024-2610, CVE-2024-2611, CVE-2024-2612, CVE-2024-2614, CVE-2024-2616, CVE-2024-3302, CVE-2024-3852, CVE-2024-3857, CVE-2024-3859, CVE-2024-3861, CVE-2024-3864, CVE-2024-4767, CVE-2024-4768, CVE-2024-4769, CVE-2024-4770, CVE-2024-4777, CVE-2024-5688, CVE-2024-5690, CVE-2024-5691, CVE-2024-5693, CVE-2024-5696, CVE-2024-5700, CVE-2024-6600, CVE-2024-6601, CVE-2024-6602, CVE-2024-6603, CVE-2024-6604, CVE-2024-6606, CVE-2024-6607, CVE-2024-6608, CVE-2024-6609, CVE-2024-6610, CVE-2024-6611, CVE-2024-6612, CVE-2024-6613, CVE-2024-6614, CVE-2024-7518, CVE-2024-7521, CVE-2024-7522, CVE-2024-7525, CVE-2024-7526, CVE-2024-7527, CVE-2024-7529, CVE-2024-7652, CVE-2024-8394, CVE-2024-9392, CVE-2024-9393, CVE-2024-9394, CVE-2024-9396, CVE-2024-9397, CVE-2024-9398, CVE-2024-9399, CVE-2024-9400, CVE-2024-9401, CVE-2025-0237, CVE-2025-0238, CVE-2025-0239, CVE-2025-0240, CVE-2025-0241, CVE-2025-0242, CVE-2025-0247, CVE-2025-0510, CVE-2025-1009, CVE-2025-1010, CVE-2025-1012, CVE-2025-1013, CVE-2025-1014, CVE-2025-1015, CVE-2025-1016, CVE-2025-1018, CVE-2025-1019, CVE-2025-10527, CVE-2025-10528, CVE-2025-10529, CVE-2025-10532, CVE-2025-10533, CVE-2025-10536, CVE-2025-11708, CVE-2025-11709, CVE-2025-11710, CVE-2025-11711, CVE-2025-11712, CVE-2025-11713, CVE-2025-11714, CVE-2025-14322, CVE-2025-14323, CVE-2025-14328, CVE-2025-14329, CVE-2025-14331, CVE-2025-1931, CVE-2025-1932, CVE-2025-1933, CVE-2025-1934, CVE-2025-1935, CVE-2025-1936, CVE-2025-1937, CVE-2025-1938, CVE-2025-1942, CVE-2025-26695, CVE-2025-26696, CVE-2025-3028, CVE-2025-3029, CVE-2025-3030, CVE-2025-3031, CVE-2025-3032, CVE-2025-3033, CVE-2025-5262, CVE-2025-5986, CVE-2025-8027, CVE-2025-8028, CVE-2025-8029, CVE-2025-8030, CVE-2025-8031, CVE-2025-8032, CVE-2025-8033, CVE-2025-8034, CVE-2025-8035, CVE-2025-8036, CVE-2025-8037, CVE-2025-9179, CVE-2025-9180, CVE-2025-9181, CVE-2025-9182, CVE-2025-9184, CVE-2025-9185, CVE-2026-0818, CVE-2026-0879, CVE-2026-0882, CVE-2026-0883, CVE-2026-0884, CVE-2026-0885, CVE-2026-0886, CVE-2026-0887, CVE-2026-0890, CVE-2026-12289, CVE-2026-12305, CVE-2026-12306, CVE-2026-12309, CVE-2026-12324, CVE-2026-2447, CVE-2026-2769, CVE-2026-2772, CVE-2026-2773, CVE-2026-2774, CVE-2026-2779, CVE-2026-2782, CVE-2026-2786, CVE-2026-2787, CVE-2026-2788, CVE-2026-2789, CVE-2026-2790, CVE-2026-3889, CVE-2026-4371, CVE-2026-4692, CVE-2026-4694, CVE-2026-4710, CVE-2026-4718, CVE-2026-4721, CVE-2026-5731, CVE-2026-8090, CVE-2026-8091, CVE-2026-8092, CVE-2026-8094

CLSA: 2026:1785560172