Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Ubuntu 11.04: USN-1401-2 Critical: Thunderbird Security Flaws

ubuntu
Calendar Grey March 23, 2012
Scroller Ubuntu
Upgrade Thunderbird to address urgent vulnerabilities impacting various Ubuntu versions reported in USN-1401-2.
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

USN-1401-1 fixed vulnerabilities in Xulrunner. This update provides the

corresponding fixes for Thunderbird.

Original advisory details:

It was discovered that a flaw in the Mozilla SVG implementation could

result in an out-of-bounds memory access if SVG elements were removed

during a DOMAttrModified event handler. If the user were tricked into

opening a specially crafted page, an attacker could exploit this to cause a

denial of service via application crash. (CVE-2011-3658)

Atte Kettunen discovered a use-after-free vulnerability in the Gecko

Rendering Engine's handling of SVG animations. An attacker could

potentially exploit this to execute arbitrary code with the privileges of

the user invoking the Xulrunner based application. (CVE-2012-0457)

Atte Kettunen discovered an out of bounds read vulnerab...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  thunderbird                     3.1.20+build1+nobinonly-0ubuntu0.11.04.1

Ubuntu 10.10:
  thunderbird                     3.1.20+build1+nobinonly-0ubuntu0.10.10.1

Ubuntu 10.04 LTS:
  thunderbird                     3.1.20+build1+nobinonly-0ubuntu0.10.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1401-2

https://ubuntu.com/security/notices/USN-1401-1

CVE-2011-3658, CVE-2012-0455, CVE-2012-0456, CVE-2012-0457,

CVE-2012-0458, CVE-2012-0461, CVE-2012-0464, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/953720

Severity
critical
Lowest
Low
Medium
High
Critical

March 23, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.