Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Thunderbird.
Software Description:
- thunderbird: Mozilla Open Source mail and newsgroup client
Details:
Bobby Holley discovered vulnerabilities in Chrome Object Wrappers (COW) and
System Only Wrappers (SOW). If a user were tricked into opening a specially
crafted page and had scripting enabled, a remote attacker could exploit
this to bypass security protections to obtain sensitive information or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2013-0773)
Frederik Braun discovered that Thunderbird made the location of the active
browser profile available to JavaScript workers. Scripting for Thunderbird
is disabled by default in Ubuntu. (CVE-2013-0774)
A use-after-free vulnerability was discovered in Thunderbird. An attacker
could potentially exploit this to execute code with the privileges of the
user invoking Thunderbird if scripting were enabled. (CVE-2013-0775)
Michal Zalewski d...
The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: thunderbird 17.0.3+build1-0ubuntu0.12.10.1 Ubuntu 12.04 LTS: thunderbird 17.0.3+build1-0ubuntu0.12.04.1 Ubuntu 11.10: thunderbird 17.0.3+build1-0ubuntu0.11.10.1 Ubuntu 10.04 LTS: thunderbird 17.0.3+build1-0ubuntu0.10.04.1 After a standard system update you need to restart Thunderbird to make all the necessary changes.
CVE-2013-0773, CVE-2013-0774, CVE-2013-0775, CVE-2013-0776,
CVE-2013-0777, CVE-2013-0778, CVE-2013-0779, CVE-2013-0780,
CVE-2013-0781, CVE-2013-0782, CVE-2013-0783, CVE-2013-0784,
https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1131110
Get the latest Linux and open source security news straight to your inbox.