Several remote vulnerabilities have been discovered in the Icedove
mail client, an unbranded version of the Thunderbird mail client. The
Common Vulnerabilities and Exposures project identifies the following
problems:
CVE-2009-0040
The execution of arbitrary code might be possible via a crafted PNG file
that triggers a free of an uninitialized pointer in (1) the png_read_png
function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.
(MFSA 2009-10)
CVE-2009-0352
It is possible to execute arbitrary code via vectors related to the
layout engine. (MFSA 2009-01)
CVE-2009-0353
It is possible to execute arbitrary code via vectors related to the
JavaScript engine. (MFSA 2009-01)
CVE-2009-0652
Bjoern Hoehrmann and Moxie Marlinspike discovered a possible spoofing
attack via Unicode box drawing characters in in...
Get the latest Linux and open source security news straight to your inbox.