Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Ubuntu 12.04 LTS: USN-1611-1 Moderate: Thunderbird Memory Flaws

ubuntu
Calendar Grey October 12, 2012
Scroller Ubuntu
Multiple vulnerabilities found in Firefox have been patched. Level up your browser to mitigate risks of unauthorized system access.
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others

discovered several memory corruption flaws in Thunderbird. If a user were

tricked into opening a malicious website and had JavaScript enabled, an

attacker could exploit these to execute arbitrary JavaScript code within

the context of another website or arbitrary code as the user invoking the

program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,

CVE-2012-4191)

David Bloom and Jordi Chancel discovered that Thunderbird did not always

properly handle the select element. If a user were tricked into opening a

malicious website and had JavaScript enabled, a remote attacker could

exploit this to conduct URL spoofing and clickjacking attacks.

(CVE-2012-3984)

Collin Jackson discovered that Thunderbird did not properly follow the

HTML5...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  thunderbird                     16.0.1+build1-0ubuntu0.12.04.1

Ubuntu 11.10:
  thunderbird                     16.0.1+build1-0ubuntu0.11.10.1

Ubuntu 11.04:
  thunderbird                     16.0.1+build1-0ubuntu0.11.04.1

Ubuntu 10.04 LTS:
  thunderbird                     16.0.1+build1-0ubuntu0.10.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1611-1

CVE-2012-3982, CVE-2012-3983, CVE-2012-3984, CVE-2012-3985,

CVE-2012-3986, CVE-2012-3988, CVE-2012-3989, CVE-2012-3990,

CVE-2012-3991, CVE-2012-3992, CVE-2012-3993, CVE-2012-3994,

CVE-2012-3995, CVE-2012-4179, CVE-2012-4180, CVE-2012-4181,

CVE-2012-4182, CVE-2012-4183, CVE-2012-4184, CVE-2012-4185,

CVE-2012-4186, CVE-2012-4187, CVE-2012-4188, CVE-2012-4191,

CVE-2012-4192, CVE-2012-4193, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1062587, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1065292

Severity
important
Lowest
Low
Medium
High
Critical

October 12, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.