Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian Lenny DSA-1830-1 Critical: Icedove Remote Code Execution

debian
Calendar Grey July 12, 2009
Debian Logo
Ubuntu addresses multiple security issues in Thunderbird, enhancing safe email exchange and safeguarding system stability.
Several remote vulnerabilities have been discovered in the Icedove mail client, an unbranded version of the Thunderbird mail client

Summary

Several remote vulnerabilities have been discovered in the Icedove
mail client, an unbranded version of the Thunderbird mail client. The
Common Vulnerabilities and Exposures project identifies the following
problems:

CVE-2009-0040

The execution of arbitrary code might be possible via a crafted PNG file
that triggers a free of an uninitialized pointer in (1) the png_read_png
function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.
(MFSA 2009-10)

CVE-2009-0352

It is possible to execute arbitrary code via vectors related to the
layout engine. (MFSA 2009-01)

CVE-2009-0353

It is possible to execute arbitrary code via vectors related to the
JavaScript engine. (MFSA 2009-01)

CVE-2009-0652

Bjoern Hoehrmann and Moxie Marlinspike discovered a possible spoofing
attack via Unicode box drawing characters in in...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: icedove
CVE IDs: CVE-2009-0040 CVE-2009-0352 CVE-2009-0353 CVE-2009-0652

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here