Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Slackware 10.2: 2005-278-02 Critical: Thunderbird Code Execution Risk

slackware
Calendar Grey October 5, 2005
Scroller Slackware
Lightning bolt security patch rolled out for Slackware 10.2 addressing shell command execution vulnerability in the email application.
New Thunderbird packages are available for Slackware 10.2 and -current to fix a security issue: MFSA 2005-59 Command-line handling on Linux allows shell execution More details abou...

Summary

Here are the details from the Slackware 10.2 ChangeLog: patches/packages/mozilla-thunderbird-1.0.7-i686-1.tgz: Upgraded to thunderbird-1.0.7. This fixes a security issue where URLs passed on the command line to the thunderbird shell script were not correctly protected against interpretation by the shell. As a result, a malicious URL could contain embedded shell commands which would then be executed as the user running Thunderbird. For more information, see: https://www.mozilla.org/en-US/security/known-vulnerabilities/ (* Security fix *) Where to find the new package: Updated package for Slackware 10.2: Updated package for Slackware -current:

Where Find New Packages

MD5 Signatures

Slackware 10.2 package: 2957fa535b1333abd2dc5204d1a4cd5d mozilla-thunderbird-1.0.7-i686-1.tgz
Slackware -current package: 2957fa535b1333abd2dc5204d1a4cd5d mozilla-thunderbird-1.0.7-i686-1.tgz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg mozilla-thunderbird-1.0.7-i686-1.tgz