Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Thunderbird.
Software Description:
- thunderbird: Mozilla Open Source mail and newsgroup client
Details:
Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others
discovered several memory corruption flaws in Thunderbird. If a user were
tricked into opening a malicious website and had JavaScript enabled, an
attacker could exploit these to execute arbitrary JavaScript code within
the context of another website or arbitrary code as the user invoking the
program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,
CVE-2012-4191)
David Bloom and Jordi Chancel discovered that Thunderbird did not always
properly handle the select element. If a user were tricked into opening a
malicious website and had JavaScript enabled, a remote attacker could
exploit this to conduct URL spoofing and clickjacking attacks.
(CVE-2012-3984)
Collin Jackson discovered that Thunderbird did not properly follow the
HTML5...
The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: thunderbird 16.0.1+build1-0ubuntu0.12.04.1 Ubuntu 11.10: thunderbird 16.0.1+build1-0ubuntu0.11.10.1 Ubuntu 11.04: thunderbird 16.0.1+build1-0ubuntu0.11.04.1 Ubuntu 10.04 LTS: thunderbird 16.0.1+build1-0ubuntu0.10.04.1 After a standard system update you need to restart Thunderbird to make all the necessary changes.
https://ubuntu.com/security/notices/USN-1611-1
CVE-2012-3982, CVE-2012-3983, CVE-2012-3984, CVE-2012-3985,
CVE-2012-3986, CVE-2012-3988, CVE-2012-3989, CVE-2012-3990,
CVE-2012-3991, CVE-2012-3992, CVE-2012-3993, CVE-2012-3994,
CVE-2012-3995, CVE-2012-4179, CVE-2012-4180, CVE-2012-4181,
CVE-2012-4182, CVE-2012-4183, CVE-2012-4184, CVE-2012-4185,
CVE-2012-4186, CVE-2012-4187, CVE-2012-4188, CVE-2012-4191,
CVE-2012-4192, CVE-2012-4193, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1062587, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1065292
Get the latest Linux and open source security news straight to your inbox.