Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Debian DSA-2406-1: Icedove Remote Attack and Crash Risks

debian
Calendar Grey February 9, 2012
Scroller Debian
Multiple security issues identified in IceDove may enable remote exploitation and system failures; users advised to apply updates for protection.
Several vulnerabilities have been discovered in Icedove, Debian's variant of the Mozilla Thunderbird code base

Summary

Several vulnerabilities have been discovered in Icedove, Debian's
variant of the Mozilla Thunderbird code base.

CVE-2011-3670
Icedove does not not properly enforce the IPv6 literal address
syntax, which allows remote attackers to obtain sensitive
information by making XMLHttpRequest calls through a proxy and
reading the error messages.

CVE-2012-0442
Memory corruption bugs could cause Icedove to crash or
possibly execute arbitrary code.

CVE-2012-0444
Icedove does not properly initialize nsChildView data
structures, which allows remote attackers to cause a denial of
service (memory corruption and application crash) or possibly
execute arbitrary code via a crafted Ogg Vorbis file.

CVE-2012-0449
Icedove allows remote attackers to cause a denial of service
(memory corruption and application crash) or possibly execute
arbitrary code via a malformed XSLT stylesheet that is
embedded in a document

For the stable distribution (squeeze), this problem has been fixed in
version 3.0.11-1+squeeze7.

We r...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: icedove
CVE ID: CVE-2011-3670 CVE-2012-0442 CVE-2012-0444 CVE-2012-0449

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.