Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

Ubuntu 11.04: USN-1254-1 Moderate: Thunderbird Threats and Updates

ubuntu
Calendar Grey December 22, 2011
Scroller Ubuntu
A series of security flaws addressed in Firefox for Debian, impacting releases 9.04, 9.10, and 10.04 LTS.
Multiple vulnerabilities have been fixed in Thunderbird.

Summary

Multiple vulnerabilities have been fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

It was discovered that CVE-2011-3004, which addressed possible privilege

escalation in addons, also affected Thunderbird 3.1. An attacker could

potentially exploit a user who had installed an add-on that used

loadSubscript in vulnerable ways. (CVE-2011-3647)

Yosuke Hasegawa discovered that the Mozilla browser engine mishandled

invalid sequences in the Shift-JIS encoding. It may be possible to trigger

this crash without the use of debugging APIs, which might allow malicious

websites to exploit this vulnerability. An attacker could possibly use this

flaw this to steal data or inject malicious scripts into web content.

(CVE-2011-3648)

Marc Schoenefeld discovered that using Firebug to profile a JavaScript file

with many functions would cause Firefox to crash. An attacker might be able

to exploit this without usin...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  thunderbird                     3.1.16+build2+nobinonly-0ubuntu0.11.04.1

Ubuntu 10.10:
  thunderbird                     3.1.16+build2+nobinonly-0ubuntu0.10.10.1

Ubuntu 10.04 LTS:
  thunderbird                     3.1.16+build2+nobinonly-0ubuntu0.10.04.1

After a standard system update you need to restart Thunderbird to make all
the necessary changes.

References

CVE-2011-3647, CVE-2011-3648, CVE-2011-3650

December 22, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.