Rocky Linux 8 [CIQ] Security Update: thunderbird / thunderbird-debuginfo / thunderbird-debugsource Multiple Vulnerabilities (crlsa-2022_6708)

high Nessus Plugin ID 359054

Synopsis

The Rocky Linux host is missing one or more security updates.

Description

The Rocky Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the CIQ crlsa-2022_6708 advisory.

* Mozilla: Leaking of sensitive information when composing a response to an HTML email with a META refresh tag (CVE-2022-3033)

* Mozilla: Bypassing FeaturePolicy restrictions on transient pages (CVE-2022-40959)

* Mozilla: Data-race when parsing non-UTF-8 URLs in threads (CVE-2022-40960)

* Mozilla: Memory safety bugs fixed in Firefox 105 and Firefox ESR 102.3 (CVE-2022-40962)

* Mozilla: Remote content specified in an HTML document that was nested inside an iframe's srcdoc attribute was not blocked (CVE-2022-3032)

* Mozilla: An iframe element in an HTML email could trigger a network request (CVE-2022-3034)

* Mozilla: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack (CVE-2022-36059)

* Mozilla: Bypassing Secure Context restriction for cookies with __Host and __Secure prefix (CVE-2022-40958)

* Mozilla: Content-Security-Policy base-uri bypass (CVE-2022-40956)

* Mozilla: Incoherent instruction cache when building WASM on ARM64 (CVE-2022-40957)

Tenable has extracted the preceding description block directly from the CIQ security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in CIQ advisory crlsa-2022_6708.

See Also

https://access.redhat.com/errata/RHSA-2022:6708

https://bugzilla.redhat.com/show_bug.cgi?id=2123255

https://bugzilla.redhat.com/show_bug.cgi?id=2123256

https://bugzilla.redhat.com/show_bug.cgi?id=2123257

https://bugzilla.redhat.com/show_bug.cgi?id=2123258

https://bugzilla.redhat.com/show_bug.cgi?id=2128792

https://bugzilla.redhat.com/show_bug.cgi?id=2128793

https://bugzilla.redhat.com/show_bug.cgi?id=2128794

https://bugzilla.redhat.com/show_bug.cgi?id=2128795

https://bugzilla.redhat.com/show_bug.cgi?id=2128796

https://bugzilla.redhat.com/show_bug.cgi?id=2128797

https://errata.build.resf.org/RLSA-2022:6708

http://www.nessus.org/u?4042993f

http://www.nessus.org/u?64d5336c

Plugin Details

Severity: High

ID: 359054

File Name: ciq_rocky_linux_8_crlsa-2022_6708.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

Vendor

Vendor Severity: Unknown

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2022-40962

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/OS/extended-third-party, Host/local_checks_enabled, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 9/26/2022

Vulnerability Publication Date: 8/31/2022

Reference Information

CVE: CVE-2022-3032, CVE-2022-3033, CVE-2022-3034, CVE-2022-36059, CVE-2022-40956, CVE-2022-40957, CVE-2022-40958, CVE-2022-40959, CVE-2022-40960, CVE-2022-40962