SciLinux: CVE-2007-1362 Thunderbird SL5.x, SL4.x, SL3,x i386/x86_64
Summary
Date: Fri, 1 Jun 2007 15:54:11 -0500Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for Thunderbird on SL5.x, SL4.x, SL3,x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis: Critical: thunderbird security updateIssue date: 2007-05-30CVE Names: CVE-2007-1362 CVE-2007-1558 CVE-2007-2867 CVE-2007-2868 CVE-2007-2869 CVE-2007-2871Several flaws were found in the way Thunderbird processed certain malformed JavaScript code. A web page containing malicious JavaScript code could cause Thunderbird to crash or potentially execute arbitrary code as the user running Thunderbird. (CVE-2007-2867, CVE-2007-2868)Several denial of service flaws were found in the way Thunderbird handled certain form and cookie data. A malicious web site that is able to set arbitrary form and cookie data could prevent Thunderbird fromfunctioning properly. (CVE-2007-1362, CVE-2007-2869)A flaw was found in the way Thunderbird processed certain APOPauthentication requests. By sending certain responses when Thunderbirdattempted to authenticate against an APOP server, a remote attacker could potentially acquire certain portions of a user's authenticationcredentials. (CVE-2007-1558)A flaw was found in the way Thunderbird displayed certain web content. Amalicious web page could generate content which could overlay userinterface elements such as the hostname and security indicators, tricking users into thinking they are visiting a different site. (CVE-2007-2871)SL 3.0.x SRPMS: thunderbird-1.5.0.12-0.1.SL3.src.rpm i386: thunderbird-1.5.0.12-0.1.SL3.i386.rpm x86_64: thunderbird-1.5.0.12-0.1.SL3.s86_64.rpmSL 4.x SRPMS: thunderbird-1.5.0.12-0.1.el4.src.rpm i386: thunderbird-1.5.0.12-0.1.el4.i386.rpm x86_64: thunderbird-1.5.0.12-0.1.el4.x86_64.rpmSL 5.x SRPMS: thunderbird-1.5.0.12-1.el5.src.rpm i386: thunderbird-1.5.0.12-1.el5.i386.rpm x86_64: thunderbird-1.5.0.12-1.el5.x86_64.rpm-Connie Sieh-Troy Dawson