Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 12.04 LTS USN-1551-1 Critical: Thunderbird Memory Flaws Exploited

ubuntu
Calendar Grey August 30, 2012
Scroller Ubuntu
Various vulnerabilities in Thunderbird patched for Ubuntu versions. Users should apply updates to safeguard against potential threats and repercussions.
Multiple security issues were fixed in Thunderbird.

Summary

Multiple security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew

Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel

Holbert discovered memory safety issues affecting Thunderbird. If the user

were tricked into opening a specially crafted E-Mail, an attacker could

exploit these to cause a denial of service via application crash, or

potentially execute code with the privileges of the user invoking

Thunderbird. (CVE-2012-1970, CVE-2012-1971)

Abhishek Arya discovered multiple use-after-free vulnerabilities. If the

user were tricked into opening a specially crafted E-Mail, an attacker

could exploit these to cause a denial of service via application crash, or

potentially execute code with the privileges of the user invoking

Thunderbird. (CVE-2012-1972, CVE-2012-1973, CVE-2012-1974, CVE-2012-19...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  thunderbird                     15.0+build1-0ubuntu0.12.04.1

Ubuntu 11.10:
  thunderbird                     15.0+build1-0ubuntu0.11.10.1

Ubuntu 11.04:
  thunderbird                     15.0+build1-0ubuntu0.11.04.1

Ubuntu 10.04 LTS:
  thunderbird                     15.0+build1-0ubuntu0.10.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1551-1

CVE-2012-1956, CVE-2012-1970, CVE-2012-1971, CVE-2012-1972,

CVE-2012-1973, CVE-2012-1974, CVE-2012-1975, CVE-2012-1976,

CVE-2012-3956, CVE-2012-3957, CVE-2012-3958, CVE-2012-3959,

CVE-2012-3960, CVE-2012-3961, CVE-2012-3962, CVE-2012-3963,

CVE-2012-3964, CVE-2012-3966, CVE-2012-3967, CVE-2012-3968,

CVE-2012-3969, CVE-2012-3970, CVE-2012-3971, CVE-2012-3972,

CVE-2012-3975, CVE-2012-3978, CVE-2012-3980, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1042165

Severity
critical
Lowest
Low
Medium
High
Critical

August 30, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.