Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 13.04 LTS: USN-1925-1 Moderate: Thunderbird Memory Safety Issues

ubuntu
Calendar Grey August 7, 2013
Scroller Ubuntu
A variety of security flaws have been mitigated in Thunderbird for Ubuntu. Ensure you implement the latest updates to protect your system from possible threats.
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Jeff Gilbert and Henrik Skupin discovered multiple memory safety issues

in Thunderbird. If the user were tricked in to opening a specially crafted

message with scripting enabled, an attacker could possibly exploit these

to cause a denial of service via application crash, or potentially execute

arbitrary code with the privileges of the user invoking Thunderbird.

(CVE-2013-1701)

It was discovered that a document's URI could be set to the URI of

a different document. If a user had scripting enabled, an attacker

could potentially exploit this to conduct cross-site scripting (XSS)

attacks. (CVE-2013-1709)

A flaw was discovered when generating a CRMF request in certain

circumstances. If a user had scripting enabled, an attacker could

potentially exploit this to conduct cross-site scripting (XSS) attacks,

or execute arbi...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  thunderbird                     17.0.8+build1-0ubuntu0.13.04.1

Ubuntu 12.10:
  thunderbird                     17.0.8+build1-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  thunderbird                     17.0.8+build1-0ubuntu0.12.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1925-1

CVE-2013-1701, CVE-2013-1709, CVE-2013-1710, CVE-2013-1713,

CVE-2013-1714, CVE-2013-1717, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1208041

August 07, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.