Alpine: thunderbird: security update to 91.3.2-r0

critical Tenable Cloud Security Plugin ID 427104

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass
restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects
Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3. (CVE-2021-38503)

- Further techniques that built on the slipstream research combined with a malicious webpage could have
exposed both an internal network's hosts as well as services running on the user's local machine. This
vulnerability affects Firefox < 85. (CVE-2021-23961)

- A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound
write. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
(CVE-2021-23994)

- When Responsive Design Mode was enabled, it used references to objects that were previously freed. We
presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability
affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88. (CVE-2021-23995)

- Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon
from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
(CVE-2021-23998)

See Also

https://security.alpinelinux.org/vuln/CVE-2021-23961

https://security.alpinelinux.org/vuln/CVE-2021-23994

https://security.alpinelinux.org/vuln/CVE-2021-23995

https://security.alpinelinux.org/vuln/CVE-2021-23998

https://security.alpinelinux.org/vuln/CVE-2021-23999

https://security.alpinelinux.org/vuln/CVE-2021-24002

https://security.alpinelinux.org/vuln/CVE-2021-29945

https://security.alpinelinux.org/vuln/CVE-2021-29946

https://security.alpinelinux.org/vuln/CVE-2021-29948

https://security.alpinelinux.org/vuln/CVE-2021-29951

https://security.alpinelinux.org/vuln/CVE-2021-29956

https://security.alpinelinux.org/vuln/CVE-2021-29957

https://security.alpinelinux.org/vuln/CVE-2021-29964

https://security.alpinelinux.org/vuln/CVE-2021-29967

https://security.alpinelinux.org/vuln/CVE-2021-29969

https://security.alpinelinux.org/vuln/CVE-2021-29970

https://security.alpinelinux.org/vuln/CVE-2021-29976

https://security.alpinelinux.org/vuln/CVE-2021-29980

https://security.alpinelinux.org/vuln/CVE-2021-29981

https://security.alpinelinux.org/vuln/CVE-2021-29982

https://security.alpinelinux.org/vuln/CVE-2021-29984

https://security.alpinelinux.org/vuln/CVE-2021-29985

https://security.alpinelinux.org/vuln/CVE-2021-29986

https://security.alpinelinux.org/vuln/CVE-2021-29987

https://security.alpinelinux.org/vuln/CVE-2021-29988

https://security.alpinelinux.org/vuln/CVE-2021-29989

https://security.alpinelinux.org/vuln/CVE-2021-29991

https://security.alpinelinux.org/vuln/CVE-2021-30547

https://security.alpinelinux.org/vuln/CVE-2021-32810

https://security.alpinelinux.org/vuln/CVE-2021-38492

https://security.alpinelinux.org/vuln/CVE-2021-38493

https://security.alpinelinux.org/vuln/CVE-2021-38495

https://security.alpinelinux.org/vuln/CVE-2021-38496

https://security.alpinelinux.org/vuln/CVE-2021-38497

https://security.alpinelinux.org/vuln/CVE-2021-38498

https://security.alpinelinux.org/vuln/CVE-2021-38500

https://security.alpinelinux.org/vuln/CVE-2021-38501

https://security.alpinelinux.org/vuln/CVE-2021-38502

https://security.alpinelinux.org/vuln/CVE-2021-38503

https://security.alpinelinux.org/vuln/CVE-2021-38504

https://security.alpinelinux.org/vuln/CVE-2021-38505

https://security.alpinelinux.org/vuln/CVE-2021-38506

https://security.alpinelinux.org/vuln/CVE-2021-38507

https://security.alpinelinux.org/vuln/CVE-2021-38508

https://security.alpinelinux.org/vuln/CVE-2021-38509

https://security.alpinelinux.org/vuln/CVE-2021-38510

https://security.alpinelinux.org/vuln/CVE-2021-43534

https://security.alpinelinux.org/vuln/CVE-2021-43535

Plugin Details

Severity: Critical

ID: 427104

Version: Revision 1.2

Type: Local

Published: 5/16/2025

Updated: 5/30/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 95.11

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-38503

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 2/26/2021

Reference Information

CVE: CVE-2021-23961, CVE-2021-23994, CVE-2021-23995, CVE-2021-23998, CVE-2021-23999, CVE-2021-24002, CVE-2021-29945, CVE-2021-29946, CVE-2021-29948, CVE-2021-29951, CVE-2021-29956, CVE-2021-29957, CVE-2021-29964, CVE-2021-29967, CVE-2021-29969, CVE-2021-29970, CVE-2021-29976, CVE-2021-29980, CVE-2021-29981, CVE-2021-29982, CVE-2021-29984, CVE-2021-29985, CVE-2021-29986, CVE-2021-29987, CVE-2021-29988, CVE-2021-29989, CVE-2021-29991, CVE-2021-30547, CVE-2021-32810, CVE-2021-38492, CVE-2021-38493, CVE-2021-38495, CVE-2021-38496, CVE-2021-38497, CVE-2021-38498, CVE-2021-38500, CVE-2021-38501, CVE-2021-38502, CVE-2021-38503, CVE-2021-38504, CVE-2021-38505, CVE-2021-38506, CVE-2021-38507, CVE-2021-38508, CVE-2021-38509, CVE-2021-38510, CVE-2021-43534, CVE-2021-43535

IAVA: 2021-A-0051-S, 2021-A-0185-S, 2021-A-0214-S, 2021-A-0246-S, 2021-A-0366-S, 2021-A-0386-S, 2021-A-0405-S, 2021-A-0461-S, 2021-A-0527-S