Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian: DSA-2317-1 Severe Remote Execution Threat in Icedove

debian
Calendar Grey October 5, 2011
Debian Logo
Multiple security flaws discovered in Icedove have been handled in the recent Debian DSA-2317-1 update. It is advised to upgrade for enhanced security.
CVE-2011-2372 Mariusz Mlynski discovered that websites could open a download dialog - which has "open" as the default action -, while a user

Summary

CVE-2011-2372

Mariusz Mlynski discovered that websites could open a download
dialog - which has "open" as the default action -, while a user
presses the ENTER key.

CVE-2011-2995

Benjamin Smedberg, Bob Clary and Jesse Ruderman discovered crashes
in the rendering engine, which could lead to the execution of
arbitrary code.

CVE-2011-2998

Mark Kaplan discovered an integer underflow in the javascript
engine, which could lead to the execution of arbitrary code.

CVE-2011-2999

Boris Zbarsky discovered that incorrect handling of the
window.location object could lead to bypasses of the same-origin
policy.

CVE-2011-3000

Ian Graham discovered that multiple Location headers might lead to
CRLF injection.

As indicated in the Lenny (oldstable) release notes, security support for
the Icedove packages in the oldstable needed to be stopped before the end
of the regular Lenny security maintenance life cycle.
You are strongly encouraged to upgrade to stable or switch to a different
mail...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: icedove
CVE ID: CVE-2011-2372 CVE-2011-2995 CVE-2011-2998 CVE-2011-2999

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here