Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian: DSA-2273-1 Critical: Icedove Remote Code Execution Problem

debian
Calendar Grey July 6, 2011
Debian Logo
Multiple vulnerabilities in Icedove have been fixed, improving user safety. An upgrade is recommended.
Several vulnerabilities have been discovered in Icedove, an unbranded version of the Thunderbird mail/news client

Summary

Several vulnerabilities have been discovered in Icedove, an unbranded
version of the Thunderbird mail/news client.

CVE-2011-0083 / CVE-2011-2363

"regenrecht" discovered two use-after-frees in SVG processing,
which could lead to the execution of arbitrary code.

CVE-2011-0085

"regenrecht" discovered a use-after-free in XUL processing, which
could lead to the execution of arbitrary code.

CVE-2011-2362

David Chan discovered that cookies were insufficiently isolated.

CVE-2011-2371

Chris Rohlf and Yan Ivnitskiy discovered an integer overflow in the
Javascript engine, which could lead to the execution of arbitrary
code.

CVE-2011-2373

Martin Barbella discovered a use-after-free in XUL processing,
which could lead to the execution of arbitrary code.

CVE-2011-2374

Bob Clary, Kevin Brosnan, Nils, Gary Kwong, Jesse Ruderman and
Christian Biesinger discovered memory corruption bugs, which may
lead to the execution of arbitrary code.

CVE-2011-2376

Luke Wagner and Gary Kwong di...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: icedove
CVE ID: CVE-2011-0083 CVE-2011-0085 CVE-2011-2362 CVE-2011-2363

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here