Explore top 10 tips to secure your open-source projects now. Read More
×
Several security issues were fixed in Thunderbird.
Software Description:
- thunderbird: Mozilla Open Source mail and newsgroup client
Details:
Nicolas Gregoire and Aki Helin discovered that when processing a malformed
embedded XSLT stylesheet, Thunderbird can crash due to memory corruption.
If the user were tricked into opening a specially crafted page, an attacker
could exploit this to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2012-0449)
It was discovered that memory corruption could occur during the decoding of
Ogg Vorbis files. If the user were tricked into opening a specially crafted
file, an attacker could exploit this to cause a denial of service via
application crash, or potentially execute code with the privileges of the
user invoking Thunderbird. (CVE-2012-0444)
Tim Abraldes discovered that when encoding certain image types the
resulting data was always ...
The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: thunderbird 10.0.2+build1-0ubuntu0.11.10.1 After a standard system update you need to restart Thunderbird to make all the necessary changes.
https://ubuntu.com/security/notices/USN-1369-1
CVE-2011-3659, CVE-2012-0442, CVE-2012-0443, CVE-2012-0444,
CVE-2012-0445, CVE-2012-0446, CVE-2012-0447, CVE-2012-0449,
CVE-2012-0452, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/923372, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/929964, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/933382
Get the latest Linux and open source security news straight to your inbox.