Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 12.10 USN-1620-2 Moderate: Thunderbird XSS Threat Mitigated

ubuntu
Calendar Grey October 30, 2012
Scroller Ubuntu
Ubuntu Security Announcement USN-1620-3 introduces critical patches for Thunderbird, resolving vulnerabilities related to potential XSS exploits and reinforcing overall security measures.
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

USN-1620-1 fixed vulnerabilities in Firefox. This update provides the

corresponding updates for Thunderbird. Please note that Thunderbird is only

affected by window.location issues through RSS feeds and extensions that

load web content.

Original advisory details:

Mariusz Mlynski and others discovered several flaws in Firefox that allowed

a remote attacker to conduct cross-site scripting (XSS) attacks.

(CVE-2012-4194, CVE-2012-4195)

Antoine Delignat-Lavaud discovered a flaw in the way Firefox handled the

Location object. If a user were tricked into opening a specially crafted

page, a remote attacker could exploit this to bypass security protections

and perform cross-origin reading of the Location object. (CVE-2012-4196)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  thunderbird                     16.0.2+build1-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  thunderbird                     16.0.2+build1-0ubuntu0.12.04.1

Ubuntu 11.10:
  thunderbird                     16.0.2+build1-0ubuntu0.11.10.1

Ubuntu 10.04 LTS:
  thunderbird                     16.0.2+build1-0ubuntu0.10.04.1

After a standard system update you need to restart Thunderbird to make all
the necessary changes.

References

https://ubuntu.com/security/notices/USN-1620-2

https://ubuntu.com/security/notices/USN-1620-1

CVE-2012-4194, CVE-2012-4195, CVE-2012-4196, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1072362

Severity
important
Lowest
Low
Medium
High
Critical

October 30, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.