Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 13.04: USN-1952-1 Critical: Thunderbird Memory Issues

ubuntu
Calendar Grey September 18, 2013
Scroller Ubuntu
Explore various enhancements in security for Thunderbird on Ubuntu 13.04 and LTS focused on resolving significant vulnerabilities.
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Multiple memory safety issues were discovered in Thunderbird. If a user

were tricked in to opening a specially crafted message with scripting

enabled, an attacker could possibly exploit these to cause a denial of

service via application crash, or potentially execute arbitrary code with

the privileges of the user invoking Thunderbird. (CVE-2013-1718)

Atte Kettunen discovered a flaw in the HTML5 Tree Builder when interacting

with template elements. If a user had scripting enabled, in some

circumstances an attacker could potentially exploit this to execute

arbitrary code with the privileges of the user invoking Thunderbird.

(CVE-2013-1720)

Alex Chapman discovered an integer overflow vulnerability in the ANGLE

library. If a user had scripting enabled, an attacker could potentially

exploit this to execute arbitrary code...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  thunderbird                     1:24.0+build1-0ubuntu0.13.04.1

Ubuntu 12.10:
  thunderbird                     1:24.0+build1-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  thunderbird                     1:24.0+build1-0ubuntu0.12.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1952-1

CVE-2013-1718, CVE-2013-1720, CVE-2013-1721, CVE-2013-1722,

CVE-2013-1724, CVE-2013-1725, CVE-2013-1728, CVE-2013-1730,

CVE-2013-1732, CVE-2013-1735, CVE-2013-1736, CVE-2013-1737,

CVE-2013-1738, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1224912

Severity
critical
Lowest
Low
Medium
High
Critical

September 18, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.