Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu: 1510-1 Critical: Thunderbird Memory Flaws and Attack Vectors

ubuntu
Calendar Grey July 17, 2012
Scroller Ubuntu
=========================================================================Ubuntu Security Notice USN-
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Benoit Jacob, Jesse Ruderman, Christian Holler, Bill McCloskey, Brian Smith,

Gary Kwong, Christoph Diehl, Chris Jones, Brad Lassey, and Kyle Huey discovered

memory safety issues affecting Thunderbird. If the user were tricked into

opening a specially crafted page, an attacker could possibly exploit these to

cause a denial of service via application crash, or potentially execute code

with the privileges of the user invoking Thunderbird. (CVE-2012-1948,

CVE-2012-1949)

Abhishek Arya discovered four memory safety issues affecting Thunderbird. If

the user were tricked into opening a specially crafted page, an attacker could

possibly exploit these to cause a denial of service via application crash, or

potentially execute code with the privileges of the user invoking Thunderbird.

(CVE-2012-1951, CVE-2012-1952, CVE-2012-1953,...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  thunderbird                     14.0+build1-0ubuntu0.12.04.1

Ubuntu 11.10:
  thunderbird                     14.0+build1-0ubuntu0.11.10.1

Ubuntu 11.04:
  thunderbird                     14.0+build1-0ubuntu0.11.04.1

Ubuntu 10.04 LTS:
  thunderbird                     14.0+build1-0ubuntu0.10.04.1

When upgrading, users should be aware of the following:

- In Ubuntu 11.04, unity-2d users may lose the ability to view drop-down menus,
context menus, and perform drag-and-drop operations in Thunderbird. This is a
known issue being tracked in https://bugs.launchpad.net/ubuntu/+source/unity-2d/+bug/1020198 and may be
fixed in a later update.

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1510-1

CVE-2012-1948, CVE-2012-1949, CVE-2012-1951, CVE-2012-1952,

CVE-2012-1953, CVE-2012-1954, CVE-2012-1955, CVE-2012-1957,

CVE-2012-1958, CVE-2012-1959, CVE-2012-1960, CVE-2012-1961,

CVE-2012-1962, CVE-2012-1963, CVE-2012-1967, https://bugs.launchpad.net/ubuntu/+source/unity-2d/+bug/1020198,

https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1024564

Severity
critical
Lowest
Low
Medium
High
Critical

July 17, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.