Critical information about security vulnerabilities in LFS and BLFS (Dated 2025-05-21)
"\"Douglas R. Reno\"" ([email protected] via blfs-dev Mailing List) <[email protected]> Wed, 21 May 2025 02:12:34 -0500
| Newsgroups | gmane.linux.lfs.beyond.devel,gmane.linux.lfs.devel,gmane.linux.lfs.support,gmane.linux.lfs.beyond.support |
|---|---|
| Message-ID | <[email protected]> |
Good morning folks (it counts as morning here, just hit 12:15am as I am writing this :) )! There have been many important security vulnerability fixes since the last email. The security updates this particular cycle have been very challenging to work with so far, not only because of personal stuff with me (hardware failures causing backlogs combined with my university classes the last two weeks) but also dealing with regressions/problems from a variety of security updates (including WebKit, Qt6, expat, libarchive, and QtWebEngine). These issues will be mentioned throughout the descriptions of the updates. The security updates in this email require special care, and many of them need to be applied to all of your systems immediately to protect them due to their severity and impacts. Please treat the issues described in this email as **urgent**. Before we go over the updates though, I would like to personally thank Joe Locash, Rainer Fiebig, Marty Jack, and Zeckma for their help in collecting security information, fixing bugs in updates, and disseminating security information. Joe has personally reached out to me a few times to let me know about issues such as libsoup and giflib, and has filed tickets for other ones that I was able to get into the book in time for this round of security advisories. Rainer has inquired about the advisories a couple of times which has helped me describe some of the issues that have come up, and Zeckma assisted me with getting a few updates in (Firefox/Thunderbird) to make things easier for this set of advisories. Joe also provided me with a helpful fix for LibreOffice due to OpenJDK, which saved me potentially several rebuilds of LibreOffice trying to fix the issue. Marty also provided me with an extremely helpful patch to fix issues with LibreOffice and poppler. Thank you all so much for your help, without it this would've been much tougher to take care of. Another important thing to mention is that **all** users who have make-ca installed need to make sure that they are on make-ca-1.16 to prevent issues with obtaining updated security certificates from Mozilla. Mozilla recently changed the domain that we get the certificates from hg.mozilla.org to hg-edge.mozilla.org, and in addition to the domain, also changed the organization that signs the certificate for the new domain. Because of that, previous versions of make-ca will no longer be able to contact Mozilla's servers to download the security certificates. In make-ca-1.16 we fixed this by shipping the correct root certificate to contact hg-edge.mozilla.org, and corrected the domain name. Users who are building stable LFS will have noticed that expat-2.6.4 is no longer available. Please download 2.7.1 instead, as 2.6.4 was pulled upstream due to security vulnerabilities. It has been tested on BLFS 12.3 systems and is confirmed to work well. This email will cover the following packages: - libxslt - PHP - Expat (LFS) - WebKitGTK - libarchive - Exim - Mercurial - Qt6 - QtWebEngine - lxml (Python Module) - libxml2 - Exempi - c-ares - Perl (LFS) - Python (LFS and BLFS) - xz (LFS) - Yelp - libsoup3 - libsoup2 - giflib - Epiphany - ghostscript - gstreamer - LibreOffice - PostgreSQL - intel-microcode - Screen - OpenJDK - Gimp - Spidermonkey - Firefox - Thunderbird **libxslt**: We'll begin with libxslt. This security update has been rated as High. Two security vulnerabilities were fixed here which could allow for arbitrary code execution, as well as crashes when processing XSL documents. Both vulnerabilities are due to use-after-free bugs. One of them happens when processing XPath context nodes, because an XPath context node can be modified but never restored when using nested XPath evaluations. Applications which use the xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal functions may be impacted. The other vulnerability happens in the xsltGetInheritedNsList function, and is related to the exclusion of result prefixes. Users who have libxslt installed should update to libxslt-1.1.43, especially since these vulnerabilities can theoretically be triggered through XHTML pages if you are using QtWebEngine as configured in the book. **PHP**: This security update has been rated as Medium. A total of seven vulnerabilities were fixed that could cause crashes, arbitrary code execution, unauthorized HTTP redirects, authentication bypasses, remote system crashes, and for invalid HTTP headers to be processed. The vulnerabilities exist in the Streams, libxml, and Core components within PHP. **ALL** users who have PHP installed and use it in the context of a web application are encouraged to update to at least PHP 8.4.5 to fix these vulnerabilities. **Expat (LFS)**: This security update has been rated as High. A security vulnerability was fixed that could result in a crash from chaining a large number of entities. The vulnerability is caused by a stack overflow, and upstream resolved it by fixing the usage of recursion for general entities in character data and attribute data, as well as for parameter entities. The crash is unfortunately very easy to trigger. This update was a little complex to put in though, as the initial version that it was fixed in (2.7.0) introduced a major regression where any application that called the XML_GetCurrentByteCount, XML_GetCurrentByteIndex, XML_GetCurrentColumnNumber, XML_GetCurrentLineNumber, and the XML_GetInputContext functions to immediately crash. It was originally discovered in the XML::Parser perl module's test suite, and we immediately brought it to upstream at https://github.com/cpan-authors/XML-Parser/issues/104 as soon as it was discovered. We recommend that all users who have Expat installed update to Expat 2.7.1 as soon as possible because of how easy the crash is to trigger, and how many applications use Expat for XML parsing behind the scenes. **WebKitGTK**: This security update has been rated as Critical. Sixteen security vulnerabilities were fixed that could result in unexpected process crashes, cross-origin data exfiltration, memory corruption, cross-site scripting attacks, type confusion (note that this only affects ARM architectures), and sandbox escapes. The sandbox escape vulnerability is known to be exploited in the wild. This update took a long time because of issues that cropped up with 32-bit systems, and 64-bit systems with less than 16GB of RAM. CMake defaults to using -O3 for the optimization level when you do a Release build, and one of the automatically generated files that WebKit creates is extremely large. It was discovered that systems with less than 16GB of RAM could not build WebKitGTK-2.48.0 or later without manually decreasing the optimization level, which we now cover in the Important note in the WebKitGTK page prior to build instructions. This unfortunately caused a significant delay as it took over a dozen attempts before I was able to come up with a workable solution. Rahul, Thomas, and Xi also took a stab at the issue at points, as well as Ken - thank you all! Because of the variety of impacts here as well as the fact that the sandbox escape is known to be exploited in the wild, all users who have WebKitGTK installed should update to 2.48.2 immediately. **libarchive**: This security update has been rated as Medium. Three security vulnerabilities were fixed here that could allow for denial of service (application crashes) or memory corruption when processing ZIP or TAR archives. The ZIP vulnerability exists in the 'bsdunzip' utility, and there is a public proof of concept exploit available - however, note that the worst impact is a crash. The TAR issues are both due to heap-based buffer overreads, and can occur when handling truncation in the middle of GNU long linknames, and when checking strftime return values. The vulnerabilities were fixed in 3.7.8, but a major regression was discovered in 3.7.8 and we thus recommend updating to libarchive-3.7.9 instead. **Exim**: This security update has been rated as High. A security vulnerability was fixed that could allow users with command line access to the server to obtain privilege escalation to root. The issue is caused by a use-after-free issue, and in BLFS systems, can occur before exim fully drops privileges to the 'exim' user depending on timing. If you have Exim installed on your system, you should update to Exim 4.98.2. **Mercurial**: This security vulnerability has been rated as Medium, because the default BLFS configuration is not impacted. If you are not using the 'hgweb' program (which is not part of the standard BLFS configuration), you may safely skip this update. If you do use the 'hgweb' program, it is vulnerable to cross-site scripting attacks. The vulnerability allows attackers to forge a link that will execute JavaScript code in the victim's browser, but note that most WSGI implementations will throw a HTTP 500 error instead of allowing the exploit to succeed. Still though, if you use the 'hgweb' functionality from Mercurial, you should update to Mercurial 7.0.1. **Qt6**: This security update has been rated as Low. A security vulnerability has been fixed that could allow for a heap buffer overflow when passing an incorrectly formatted Markdown file to an application that utilizes QTextMarkdownImporter. The only known impacts at this time are application crashes. There are two approaches to fixing this vulnerability. One way is to apply the official Qt patch to your system if you have Qt 6.8.x installed. That patch can be found at https://download.qt.io/official_releases/qt/6.8/CVE-2025-3512-qtbase-6.8.diff, but note that the BLFS team has not tested this approach (though there is a very very low chance that it doesn't work). The other option would be to upgrade your system to Qt 6.9.0. This involves a lot of risk, and can be complex. The risk being that a lot of private API that applications were depending on was changed in Qt 6.9.0. These issues start to crop up in Plasma, libportal, and LXQt (due to a dependency on a Plasma component). If you decide to update to Qt 6.9.0, you will need to rebuild libportal with the patch in the development book to fix usage of private API, as well as rebuild Plasma with the instructions in the development book again because of private API usage. If you use LXQt and have only installed the minimal set of KDE components necessary to use it, you will need to rebuild layer-shell-qt also because of private API usage. After updating Qt you will also need to rebuild anything that installs files in /opt/qt6 - in BLFS that includes qca and qcoro. Most users will very likely not be impacted by this vulnerability, so the risk in skipping this update is Low. However, if you do decide to update to Qt 6.9.0, please keep the above information in mind. **QtWebEngine**: This security update has been rated as Critical. In QtWebEngine-6.9.0, fifteen security vulnerabilities were fixed that could allow for sensitive system data exfiltration, user interface spoofing, remote code execution, arbitrary code execution, and sandbox escapes. The vulnerabilities are in a variety of components in the bundled copy of Chromium, including GPU, 7-zip, Network, V8, Browser, UI, DevTools, Media, Media Stream, PDFium, WebRTC, and Inspector. The WebRTC vulnerability is known to be exploited in the wild, and is a sandbox escape. It is the exact same vulnerability fixed in WebKitGTK, and we thus recommend that all users update this package immediately. However, there was a regression discovered after the release of QtWebEngine-6.9.0, where GPU acceleration was broken. This was another one of those challenging bugs to fully resolve in BLFS, since there were many moving parts involved. We've developed a patch with commits from upstream that fixes the issue, however in addition to applying the patch users must update Falkon to the latest version as well. That has been tested to work on a BLFS 12.3 system though without modifications. All users with QtWebEngine should update to QtWebEngine 6.9.0 with the patch immediately, and then rebuild Falkon to ensure that GPU acceleration continues to function correctly. **lxml (Python Module)**: This security update has been rated as High. In lxml-5.4.0, the bundled copies of libxml2 and libxslt were updated to fix five security vulnerabilities. The vulnerabilities allow for arbitrary code execution and crashes when processing crafted XML and XSLT documents. The issues occur due to heap-based buffer underreads, stack buffer overflows, out of bounds memory accesses, and use-after-free issues. Users who have the lxml python module installed should update to lxml-5.4.0. **libxml2**: This security update has been rated as High. In libxml2-2.14.2 (and 2.13.8), two security vulnerabilities were fixed that could result in a denial of service or arbitrary code execution when processing XML documents. One of the issues occurs in the xmlSchemalDCFillNodeTables function, and is due to a heap-based buffer under read. To exploit that vulnerability, an attacker must validate the XML document against an XML schema with certain identity constraints (although a crafted XML schema can be used as well). The other vulnerability is in the Python API, and it causes an out of bounds memory access due to an incorrect return value when using the xmlPythonFileRead and xmlPythonFileReadRaw functions. The issue occurs because of a difference in bytes and characters. This update brings something that requires special care. libxml2-2.14 is ABI incompatible with libxml2-2.13, and many packages on the system must be recompiled in order to fix the vulnerability. If you update to libxml2-2.14, you must also update libxkbcommon and localsearch to fix critical runtime issues that libxml2-2.14 causes in those packages. As a result, we recommend that users stay on the libxml2-2.13 series and update to 2.13.8 instead of upgrading to 2.14 on an existing system. **Exempi**: This security update has been rated as Medium. Before we go any further on this one, I want to note that even though the vulnerabilities look severe here, they are rated as Medium by upstream because they are challenging to exploit and require the usage of advanced XMP features. In Exempi-2.6.6, five security vulnerabilities were fixed in the bundled Adobe XML Toolkit SDK that could allow for out-of-bounds reads. The impacts include denial of service (application crashes), and information disclosure of sensitive memory when processing crafted XMP metadata. Updating to Exempi-2.6.6 is recommended if you manipulate files with XMP metadata. **c-ares**: This security update has been rated as High. A security vulnerability was fixed that could allow for a crash when processing DNS queries where a DNS Cookie Failure occurs, when an upstream server does not properly support EDNS, or potentially on TCP queries if the remote server closed the connection immediately after a response. The crash occurs due to a use-after-free issue in the read_answers() function, and is theoretically exploitable by remote attackers if the attacker can flood your system with ICMP UNREACHABLE packets - but in order for this to happen, the attackers must have control over the upstream nameserver. The vulnerability has been rated as High upstream due to the fact that it's attack vector is Network, and the impact is a remotely exploitable crash, but note that the attack complexity is High. Users who have c-ares installed should update to c-ares-1.34.5. **Perl (LFS)**: This security update has been rated as High. A security vulnerability was fixed that could allow for a denial of service or arbitrary code execution when transliterating non-ASCII bytes. The issue is caused by a heap buffer overflow, and a subsequent out of bounds write. A simple one-line reproducer is available that demonstrates a crash caused by the vulnerability. Users should update to Perl 5.40.2. If you are on an older version of LFS which has one of Perl 5.38, 5.36, or 5.34 - the Perl developers have put out new releases for those lines! You'll want to update to 5.38.4, 5.36.3, or 5.34.3. **Python (LFS and BLFS): This security update has been rated as Medium. In Python-3.13.3, two security vulnerabilities were fixed that could allow for unbounded memory usage (causing a denial of service by consuming all of the RAM on your system), and for email header spoofing. However, after the release of 3.13.3, an additional security vulnerability was discovered that can allow for a crash when using the unicode_escape encoding or an error handler when decoding bytes with the bytes.decode() function. The unbounded memory usage issue occurs while writing temporary files with the tempfile.SpooledTemporaryFile.writelines() function, as the function only checks whether it should roll over after the entire line's iterator is exhausted. The email header spoofing vulnerability occurs when using RFC2047 encoding and using the as_bytes function with the policy=default behavior. Users should update to Python 3.13.3 with the security fixes patch that we implemented earlier for the unicode_escape vulnerability (thank you to Joe Locash for filing a ticket in BLFS for it). **xz (LFS)**: This security update has been rated as High. A security vulnerability was resolved that could allow for invalid input when decompressing a XZ file to cause a denial of service (crash) or arbitrary code execution. The issue is caused by a heap use after free, but it can also write to an address based on the null pointer plus an offset. This can be used to inject bytes into memory. Applications and libraries which use the lzma_stream_decoder_mt function are impacted, but note that the vulnerability only gets triggered when decompressing crafted files. That being said though, all users are recommended to update to xz-5.8.1 as soon as possible especially if you decompress unknown/untrusted xz files. **yelp**: This security update has been rated as High. This one is a bit special, as it really should be rated as Critical. A security vulnerability was found in Yelp-42.2 that allows for help documents to execute arbitrary JavaScript and also read arbitrary files on the disk. Upstream has **not** released a patched version of yelp/yelp-xsl to resolve the problem, but the BLFS team has adopted some patches from upstream to resolve it ourselves. The patches resolve the issue by implementing a Content Security Policy through some calls to WebKit, which prevent JavaScript code from being executed. There is a public writeup and exploit available, and it shows just how dangerous this vulnerability is. The exploit demonstrates reading a user's SSH private key via a crafted help document, and exfiltrating it to another system. Because of that, **ALL** BLFS USERS WHO HAVE YELP INSTALLED SHOULD APPLY THE PATCHES AS SOON AS POSSIBLE. Note that patches will need to be applied to both yelp-xsl and yelp for the mitigation of the vulnerability to be successful. **libsoup3*: This security update has been rated as Critical. In libsoup3, ten security vulnerabilities were fixed that could allow for remotely exploitable crashes, remote code execution, and memory corruption. The vulnerabilities happen in a variety of different functions inside of libsoup3, including append_param_quoted(), sniff_unknown(), sniff_feed_or_html(), soup_headers_parse_request(), sniff_mp4(), soup_auth_digest_authenticate(), and soup_message_headers_get_content_disposition(). These functions are used in many programs that use libsoup3, and the issues occur due to a variety of problems including integer overflows, segmentation faults, heap buffer over reads, out of bounds reads, NULL pointer dereferences, and double frees. Unfortunately there are many more vulnerabilities in libsoup3 which have been reported upstream but have not been properly fixed at this time, but please keep an eye on the security advisories to be informed on when more are fixed. All users who have libsoup3 should update to 3.6.5 as soon as possible. Special thanks goes to Joe Locash for reporting the initial list and to both Joe and Xi for helping keep track of the new issues. **libsoup2**: This security update has been rated as Critical. In libsoup2, fourteen security vulnerabilities were fixed that could allow for remotely exploitable crashes, remote code execution, HTTP Request Smuggling, and memory corruption. These are extremely similar to the vulnerabilities fixed in libsoup3, but with some that are also specific to libsoup2. Because libsoup2 is no longer maintained upstream, and the packages which use it are abandoned, it has been removed from the development books and will not be available in BLFS 12.4. That has included archiving AbiWord and libgdata as they are both abandoned. However, we have created a final patch to fix the fourteen security vulnerabilities, and the patch can be found at https://linuxfromscratch.org/patches/downloads/libsoup/libsoup-2.74.3-security_fixes-1.patch. Users who have libsoup2 installed should discontinue use and migrate to libsoup3 where possible, but the patch that we have created and tested passes the test suite cleanly and does not break libgdata or AbiWord. **giflib**: This security update has been rated as High. Several security vulnerabilities were discovered in giflib-5.2.2, but only one of them has a functional patch. That vulnerability has been assigned four different individual CVEs, and it causes a buffer overflow in the gif2rgb utility. Upon the issue being reported to us, we adopted a patch from OpenMandriva which fixes this particular vulnerability, but please stay tuned to the security advisories for future updates which fix other issues in giflib that are currently known (and reported to upstream), but have not been fixed at this time. Rebuilding giflib with the patch now implemented in the development books is recommended. **Epiphany**: This security update has been rated as High. In Epiphany-48.1, a security vulnerability was fixed that allows websites to trigger URL handlers with no user interaction or warning. If the handler application that is called is vulnerable to other issues, remote code execution would be possible under the user's current context. Before 48.1, the browser did not prevent external URL handler applications from launching without a user's permission, and also did not warn users about the applications opening. As an example, this could be chained with the Yelp vulnerability to trigger Yelp into launching a malicious Help document from a server. However, two regressions were introduced with this update which cause crashes when downloading opened files and opening Incognito windows, so we recommend that all users update to Epiphany 48.3 instead if they have Epiphany installed. **ghostscript**: This security update has been rated as Critical. In ghostscript-10.05.0, nine security vulnerabilities were fixed that could result in remote code execution or arbitrary file accesses. The arbitrary file execution vulnerability occurs due to truncated paths with invalid UTF-8 characters, but the remote code execution vulnerabilities occur due to buffer overflows in various contexts, including processing PDF files, serializing fonts (common when printing!), utilizing BJ10V, DOCXWRITE TXTWRITE, and NPDL devices, and when converting glyphs to Unicode. All users who have ghostscript installed are encouraged to update to ghostscript-10.05.0 or later as soon as possible, especially if they use a printer or use ghostscript for PDF manipulation. **gstreamer**: This security update has been rated as High. In gst-plugins-bad-1.26.1, a security vulnerability was fixed that can allow for crashes or remote code execution (in the context of a web browser) when processing malformed streams in a video file using the H.265 codec. The issue is caused by a stack buffer overflow that occurs when processing slice headers. The CVE number is still reserved, but some basic information can be found upstream at https://gstreamer.freedesktop.org/security/sa-2025-0001.html. All users who have the gstreamer stack installed should update to update the stack to 1.26.1 as soon as possible. **LibreOffice**: This security update has been rated as Critical. Note that this vulnerability only impacts users who use LibreOffice to open or modify PDF documents. In LibreOffice-25.2.2.2, a security vulnerability was fixed that allows for PDF signature forgery when using the adbe.pkcs7.sha1 SubFilter. The bug causes invalid signatures to be accepted as valid, and NVD has rated it as Critical because it meets criteria including "Improper Verification of Cryptographic Signature" and "PDF Signature Spoofing by Improper Validation". Users who use LibreOffice for reading or modifying PDFs should update to LibreOffice-25.2.2.2 as soon as possible, especially as this could allow for phishing attacks. **PostgreSQL**: This security update has been rated as Medium. In PostgreSQL-17.5, a security vulnerability was fixed that could allow for a database input provider to achieve a temporary denial of service on any platform where a 1-byte over-read can trigger process termination. The issue occurs when performing GB18030 encoding validation, and it's classified as a buffer over-read. Unfortunately it affects libpq as well as the database server, so client applications can also crash as well as the database server itself. Note that text must fail validation for this vulnerability to get exploited. Users who have PostgreSQL installed should consider upgrading to PostgreSQL 17.5 depending on the context in which they use the database server (or client applications), such as when processing untrusted input. If you are just using PostgreSQL as a build dependency for something else, there is no need to update. If you are on older versions of BLFS that use older versions of PostgreSQL, versions 16.9, 15.13, 14.18, and 13.21 have also been made available! **intel-microcode**: This security update has been rated as Medium. In intel-microcode-20250512, eight processor level security issues were addressed. Six of the vulnerabilities allow for information disclosure, and two allow for denial of service. These vulnerabilities apply to a variety of different processors, including the 8th, 9th, 10th, 11th, 12th, 13th, and 14th generation of Intel Core CPUs, the Atom P6000 family, various Celeron and Pentium CPUs, the Core Ultra family, the Intel Xeon Scalable CPU family, the Xeon E processor family, the Xeon 6 processor family, and the Xeon W processor family. Users with Intel CPUs are encouraged to review the security advisory to determine if their CPU is affected, and update the microcode if they are. In the future, we may add fwupd which may allow users to install BIOS updates to fix these issues instead, depending on if their hardware is supported by LVFS. **Screen**: This security update has been rated as High. In Screen-5.0.1, five security vulnerabilities were fixed that could allow for users to reliably escalate privileges to root, for allowing attackers to determine if files exist, for TTY hijacking while attaching to a multi-user session, for race conditions when sending signals, and for PTYs to be created world-writable. A serious buffer overflow bug caused by a bad strncpy() was also fixed in this release. The default configuration in BLFS is to install Screen as setuid-root, and thus all systems with Screen installed are impacted by these vulnerabilities. Some of the vulnerabilities date back to around 2005. If you have Screen installed please update to Screen-5.0.1 immediately. More details about this set of vulnerabilities can be found at https://seclists.org/oss-sec/2025/q2/117 **OpenJDK**: This security update has been rated as High. In OpenJDK-24.0.1, three security vulnerabilities were fixed that could allow for remote code execution, arbitrary code execution, and unauthorized data modification. No user interaction, nor privileges, are required to exploit these vulnerabilities. The vulnerabilities are in the JSSE, 2D, and Compiler components. The JSSE and 2D vulnerabilities impact all versions of Java after JDK 8, while the Compiler vulnerability only impacts JDK 21 and higher. All users who have Java installed should update to OpenJDK-24.0.1, especially if you are running a networked application. If you update to OpenJDK-24.0.1, please update to fop-2.11 at the same time and update to Libreoffice-25.2.3.2 to work around issues with the removal of the Java Security Manager API. **Gimp**: This security update has been rated as High. In Gimp-3.0.4, a security vulnerability was fixed that could allow for remote code execution when processing a crafted .ICO file. The vulnerability is caused by an integer overflow. No CVE has been assigned yet, but there is a Zero Day Initiative identifier assigned to the vulnerability. There is a proof of concept exploit available that corrupts Gimp's internal state. Given that it's a remote code execution vulnerability, we've decided to go ahead with filing an advisory for it even though the only information available is the bug report and the fix (which has been officially released). All users who have Gimp installed that may read/modify .ICO files should update to Gimp-3.0.4, but note that you must update to babl-0.1.114 and gegl-0.4.62 at the same time. Users who are not reading/modifying .ICO files can ignore this security update. **Spidermonkey**: This security update has been rated as Critical. If there were a higher rating than Critical, I would assign it to this and the two updates following this one. At the Vancouver Pwn2Own conference, two critical security vulnerabilities were demonstrated where attackers were able to read and write out of bounds memory through executing malicious JavaScript. This allows for JavaScript manipulation as well as remote code execution. All users who have SpiderMonkey installed **urgently** need to install Spidermonkey-128.10.1. Do NOT delay with this update, please update immediately! **Firefox**: This security update has been rated as Critical. In Firefox-128.10.1 (and previous versions dating back to 128.9.0 which was the last time an advisory was filed), a total of nine security vulnerabilities were fixed. These vulnerabilities allow for remote code execution, URL bar spoofing, sandbox escapes, and unsafe attribute access (leading to out of bounds memory access and memory corruption). Most of these vulnerabilities are exploitable via standard web browsing. Two of the remote code execution vulnerabilities are known to be exploited in the wild. At the Vancouver Pwn2Own conference, two critical security vulnerabilities were demonstrated where attackers were able to read and write out of bounds memory through executing malicious JavaScript. This allows for JavaScript manipulation as well as remote code execution. **ALL USERS WHO HAVE FIREFOX INSTALLED MUST UPDATE IMMEDIATELY TO PROTECT THEIR SYSTEMS!!** **Thunderbird**: This security update has been rated as Critical. Note the several additional critical impacts in addition to the remote code execution issues shared by Spidermonkey and Firefox. In Thunderbird-128.10.2esr (as well as versions dating back to 128.9.1), eighteen security vulnerabilities were fixed. These vulnerabilities allow for remote code execution, URL bar spoofing, arbitrary code execution, exfiltration of credentials to remote attackers via compromised emails and attachments, information disclosure of a directory listing of the contents of /tmp, UI misrepresentation of attachment URLs (leading to possible phishing attacks), remotely exploitable crashes, sandbox escapes, unauthorized and unsolicited file downloads to arbitrary locations on a user's hard disk, JavaScript execution via malicious PDF attachments, and tracking links in attachments bypassing remote content blocking. This may be one of the most serious and dangerous set of vulnerabilities I have seen in my entire 11+ years working on LFS/BLFS. Note that Thunderbird is also impacted by the same remote code execution issues fixed in Spidermonkey and Firefox. **ALL USERS WHO HAVE THUNDERBIRD INSTALLED MUST UPDATE IMMEDIATELY TO PROTECT THEIR SYSTEMS!!** This was quite the long set of security updates, and there's a lot to unpack here. I know I've said so several times, but I must urge everyone to take these updates seriously and update as soon as humanly possible to protect your systems (as well as your data and credentials, especially in the case of Thunderbird/Firefox/Spidermonkey). In all of my years working on the books, this is probably the largest set of significant vulnerabilities I have ever seen, in a very large sprawl of packages. Please take these issues seriously, and do not delay with updating your systems. - Douglas Reno -- http://lists.linuxfromscratch.org/sympa/info/blfs-dev Unsubscribe: See the above information page