Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Debian Icedove Update: DSA-3061-1 Critical Memory Issues and DoS Risk

debian
Calendar Grey October 31, 2014
Debian Logo
Various vulnerabilities in Icedove pose risks related to memory corruption and possible code execution. A system update is strongly advised for all users.
Multiple security issues have been found in Icedove, Debian's version of the Mozilla Thunderbird mail and news client: Multiple memory safety errors, buffer overflows, use-after-fr...

Summary

Multiple security issues have been found in Icedove, Debian's version of
the Mozilla Thunderbird mail and news client: Multiple memory safety
errors, buffer overflows, use-after-frees and other implementation
errors may lead to the execution of arbitrary code or denial of service.

This update updates Iceweasel to the ESR31 series of Thunderbird. In
addition Enigmail was updated to version 1.7.2-1~deb7u1 to ensure
compatibility with the new upstream release.

For the stable distribution (wheezy), these problems have been fixed in
version 31.2.0-1~deb7u1.

For the unstable distribution (sid), these problems have been fixed in
version 31.2.0-1.

We recommend that you upgrade your icedove packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: icedove
CVE ID: CVE-2014-1574 CVE-2014-1576 CVE-2014-1577 CVE-2014-1578

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here