Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Debian: DSA-2556-1 High Risk: Icedove Remote Code Vulnerability

debian
Calendar Grey October 7, 2012
Debian Logo
Urgent patch issued for Icedove targets various remote vulnerabilities. Users affected should upgrade promptly.
Several vulnerabilities were discovered in Icedove, Debian's version of the Mozilla Thunderbird mail and news client

Summary

Several vulnerabilities were discovered in Icedove, Debian's version
of the Mozilla Thunderbird mail and news client.

This includes several instances of use-after-free and buffer overflow
issues. The reported vulnerabilities could lead to the execution of
arbitrary code, and additionally to the bypass of content-loading
restrictions via the location object.

For the stable distribution (squeeze), this problem has been fixed in
version 3.0.11-1+squeeze13.

For the testing distribution (wheezy), this problem has been fixed in
version 10.0.7-1.

For the unstable distribution (sid), this problem has been fixed in
version 10.0.7-1.


We recommend that you upgrade your icedove packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/




Package: icedove
CVE ID: CVE-2012-1970 CVE-2012-1972 CVE-2012-1973 CVE-2012-1974

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here