Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Debian: DSA-2297-1 Icedove Remote Code Execution Advisory

debian
Calendar Grey August 21, 2011
Debian Logo
Icebird encountered various vulnerabilities resulting in potential remote code execution. Users impacted should consider upgrading to a secure version.
Several vulnerabilities have been discovered in Icedove, an unbranded version of the Thunderbird mail/news client

Summary

Several vulnerabilities have been discovered in Icedove, an unbranded
version of the Thunderbird mail/news client.

CVE-2011-0084

"regenrecht" discovered that incorrect pointer handling in the SVG
processing code could lead to the execution of arbitrary code.

CVE-2011-2378

"regenrecht" discovered that incorrect memory management in DOM
processing could lead to the execution of arbitrary code.

CVE-2011-2981

"moz_bug_r_a_4" discovered a Chrome privilege escalation
vulnerability in the event handler code.

CVE-2011-2982

Gary Kwong, Igor Bukanov, Nils and Bob Clary discovered memory
corruption bugs, which may lead to the execution of arbitrary code.

CVE-2011-2983

"shutdown" discovered an information leak in the handling of
RegExp.input.

CVE-2011-2984

"moz_bug_r_a4" discovered a Chrome privilege escalation vulnerability.


As indicated in the Lenny (oldstable) release notes, security support for
the Icedove packages in the oldstable needed to be stopped before the end
of the regu...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: icedove
CVE ID: CVE-2011-0084 CVE-2011-2378 CVE-2011-2981 CVE-2011-2982

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here