Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 12.04 LTS USN-1551-2 Moderate: Thunderbird Message Editor Problem

ubuntu
Calendar Grey September 28, 2012
Scroller Ubuntu
Debian Security Notice DSN-1234-1 outlines resolutions for Firefox vulnerabilities impacting various editions.
USN-1551-1 introduced regressions in Thunderbird.

Summary

USN-1551-1 introduced regressions in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

USN-1551-1 fixed vulnerabilities in Thunderbird. The new package caused a

regression in the message editor and certain performance regressions as

well. This update fixes the problems.

Original advisory details:

Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew

Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel

Holbert discovered memory safety issues affecting Thunderbird. If the user

were tricked into opening a specially crafted E-Mail, an attacker could

exploit these to cause a denial of service via application crash, or

potentially execute code with the privileges of the user invoking

Thunderbird. (CVE-2012-1970, CVE-2012-1971)

Abhishek Arya discovered multiple use-after-free vulnerabilities. If the

user were tricked into opening a specially crafted E-Mail,...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  thunderbird                     15.0.1+build1-0ubuntu0.12.04.1
  thunderbird-globalmenu          15.0.1+build1-0ubuntu0.12.04.1

Ubuntu 11.10:
  thunderbird                     15.0.1+build1-0ubuntu0.11.10.1
  thunderbird-globalmenu          15.0.1+build1-0ubuntu0.11.10.1

Ubuntu 11.04:
  thunderbird                     15.0.1+build1-0ubuntu0.11.04.1
  thunderbird-globalmenu          15.0.1+build1-0ubuntu0.11.04.1

Ubuntu 10.04 LTS:
  thunderbird                     15.0.1+build1-0ubuntu0.10.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1551-2

https://ubuntu.com/security/notices/USN-1551-1

https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1049428

September 28, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.