Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Ubuntu 13.04 USN-1823-1 Critical: Thunderbird Memory Safety Issues

ubuntu
Calendar Grey May 14, 2013
Scroller Ubuntu
Recent patches address several security vulnerabilities in Thunderbird for Ubuntu platforms. Stay informed about the newest fixes and potential risks.
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Multiple memory safety issues were discovered in Thunderbird. If the user

were tricked into opening a specially crafted message with scripting

enabled, an attacker could possibly exploit these to cause a denial of

service via application crash, or potentially execute code with the

privileges of the user invoking Thunderbird. (CVE-2013-0801,

CVE-2013-1669)

Cody Crews discovered that some constructors could be used to bypass

restrictions enforced by their Chrome Object Wrapper (COW). If a user had

scripting enabled, an attacker could exploit this to conduct cross-site

scripting (XSS) attacks. (CVE-2013-1670)

A use-after-free was discovered when resizing video content whilst it is

playing. If a user had scripting enabled, an attacker could potentially

exploit this to execute code with the privileges of the user invoki...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  thunderbird                     17.0.6+build1-0ubuntu0.13.04.1

Ubuntu 12.10:
  thunderbird                     17.0.6+build1-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  thunderbird                     17.0.6+build1-0ubuntu0.12.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1823-1

CVE-2013-0801, CVE-2013-1669, CVE-2013-1670, CVE-2013-1674,

CVE-2013-1675, CVE-2013-1676, CVE-2013-1677, CVE-2013-1678,

CVE-2013-1679, CVE-2013-1680, CVE-2013-1681, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1178649

Severity
critical
Lowest
Low
Medium
High
Critical

May 14, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.