Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Ubuntu: 1891-1 Critical: Thunderbird Memory Problems and Risks

ubuntu
Calendar Grey June 26, 2013
Scroller Ubuntu
Addressed multiple issues with Thunderbird impacting Ubuntu functionality. It is recommended for users to upgrade for enhanced efficiency.
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Multiple memory safety issues were discovered in Thunderbird. If the user

were tricked into opening a specially crafted message with scripting

enabled, an attacker could possibly exploit these to cause a denial of

service via application crash, or potentially execute arbitrary code with

the privileges of the user invoking Thunderbird. (CVE-2013-1682)

Abhishek Arya discovered multiple use-after-free bugs. If the user were

tricked into opening a specially crafted message with scripting enabled,

an attacker could possibly exploit these to execute arbitrary code with

the privileges of the user invoking Thunderbird. (CVE-2013-1684,

CVE-2013-1685, CVE-2013-1686)

Mariusz Mlynski discovered that user defined code within the XBL scope of

an element could be made to bypass System Only Wrappers (SOW). If a user

had scripting ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  thunderbird                     17.0.7+build1-0ubuntu0.13.04.1

Ubuntu 12.10:
  thunderbird                     17.0.7+build1-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  thunderbird                     17.0.7+build1-0ubuntu0.12.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1891-1

CVE-2013-1682, CVE-2013-1684, CVE-2013-1685, CVE-2013-1686,

CVE-2013-1687, CVE-2013-1690, CVE-2013-1692, CVE-2013-1693,

CVE-2013-1694, CVE-2013-1697, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1193919

Severity
critical
Lowest
Low
Medium
High
Critical

June 26, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.