Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Thunderbird.
Software Description:
- thunderbird: Mozilla Open Source mail and newsgroup client
Details:
USN-1430-1 fixed vulnerabilities in Firefox. This update provides the
corresponding fixes for Thunderbird.
Original advisory details:
Bob Clary, Christian Holler, Brian Hackett, Bobby Holley, Gary Kwong,
Hilary Hall, Honza Bambas, Jesse Ruderman, Julian Seward, and Olli Pettay
discovered memory safety issues affecting Firefox. If the user were tricked
into opening a specially crafted page, an attacker could exploit these to
cause a denial of service via application crash, or potentially execute
code with the privileges of the user invoking Firefox. (CVE-2012-0467,
CVE-2012-0468)
Aki Helin discovered a use-after-free vulnerability in XPConnect. An
attacker could potentially exploit this to execute arbitrary code with the
privileges of the user invoking Firefox. (CVE-2012-0469)
Atte Kettunen discove...
The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: thunderbird 12.0.1+build1-0ubuntu0.12.04.1 Ubuntu 11.10: thunderbird 12.0.1+build1-0ubuntu0.11.10.1 Ubuntu 11.04: thunderbird 12.0.1+build1-0ubuntu0.11.04.1 Ubuntu 10.04 LTS: thunderbird 12.0.1+build1-0ubuntu0.10.04.1 After a standard system update you need to restart Thunderbird to make all the necessary changes.
https://ubuntu.com/security/notices/USN-1430-3
https://ubuntu.com/security/notices/USN-1430-1
CVE-2011-1187, CVE-2011-3062, CVE-2012-0467, CVE-2012-0468,
CVE-2012-0469, CVE-2012-0470, CVE-2012-0471, CVE-2012-0473,
CVE-2012-0474, CVE-2012-0475, CVE-2012-0477, CVE-2012-0478,
CVE-2012-0479, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/987305
Get the latest Linux and open source security news straight to your inbox.