Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 12.10: USN-1748-1 Moderate: Thunderbird Denial Of Service

ubuntu
Calendar Grey February 26, 2013
Scroller Ubuntu
Enhancing your Ubuntu environments with crucial updates is vital to address vulnerabilities in Thunderbird, preventing exposure to potential security risks
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Bobby Holley discovered vulnerabilities in Chrome Object Wrappers (COW) and

System Only Wrappers (SOW). If a user were tricked into opening a specially

crafted page and had scripting enabled, a remote attacker could exploit

this to bypass security protections to obtain sensitive information or

potentially execute code with the privileges of the user invoking

Thunderbird. (CVE-2013-0773)

Frederik Braun discovered that Thunderbird made the location of the active

browser profile available to JavaScript workers. Scripting for Thunderbird

is disabled by default in Ubuntu. (CVE-2013-0774)

A use-after-free vulnerability was discovered in Thunderbird. An attacker

could potentially exploit this to execute code with the privileges of the

user invoking Thunderbird if scripting were enabled. (CVE-2013-0775)

Michal Zalewski d...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  thunderbird                     17.0.3+build1-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  thunderbird                     17.0.3+build1-0ubuntu0.12.04.1

Ubuntu 11.10:
  thunderbird                     17.0.3+build1-0ubuntu0.11.10.1

Ubuntu 10.04 LTS:
  thunderbird                     17.0.3+build1-0ubuntu0.10.04.1

After a standard system update you need to restart Thunderbird to make all
the necessary changes.

References

CVE-2013-0773, CVE-2013-0774, CVE-2013-0775, CVE-2013-0776,

CVE-2013-0777, CVE-2013-0778, CVE-2013-0779, CVE-2013-0780,

CVE-2013-0781, CVE-2013-0782, CVE-2013-0783, CVE-2013-0784,

https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1131110

=========================================================================Ubuntu Security Notice USN-1748-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.