Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 12.xx: USN-1791-1 Moderate: Thunderbird Memory Safety Risks

ubuntu
Calendar Grey April 8, 2013
Scroller Ubuntu
Several vulnerabilities have been addressed in Thunderbird impacting various versions of Ubuntu; ensure your system is updated for enhanced security.
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan

Sreckovic and Joe Drew discovered multiple memory safety issues affecting

Thunderbird. If the user were tricked into opening a specially crafted

message with scripting enabled, an attacker could possibly exploit these

to cause a denial of service via application crash, or potentially

execute code with the privileges of the user invoking Thunderbird.

(CVE-2013-0788)

Ambroz Bizjak discovered an out-of-bounds array read in the

CERT_DecodeCertPackage function of the Network Security Services (NSS)

libary when decoding certain certificates. An attacker could potentially

exploit this to cause a denial of service via application crash.

(CVE-2013-0791)

Mariusz Mlynski discovered that timed history navigations could be used to

load arbitrary websites with ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  thunderbird                     17.0.5+build1-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  thunderbird                     17.0.5+build1-0ubuntu0.12.04.1

Ubuntu 11.10:
  thunderbird                     17.0.5+build1-0ubuntu0.11.10.1

Ubuntu 10.04 LTS:
  thunderbird                     17.0.5+build1-0ubuntu0.10.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1791-1

CVE-2013-0788, CVE-2013-0791, CVE-2013-0793, CVE-2013-0795,

CVE-2013-0796, CVE-2013-0800, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1162043

Severity
important
Lowest
Low
Medium
High
Critical

April 08, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.