Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Ubuntu 13.10: 2010-1 Moderate: Thunderbird Memory Flaws and Threats

ubuntu
Calendar Grey October 31, 2013
Scroller Ubuntu
A series of security issues resolved in Thunderbird impacting various Ubuntu versions. Adhere to the update guidelines to ensure your protection.
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Multiple memory safety issues were discovered in Thunderbird. If a user

were tricked in to opening a specially crafted message with scripting

enabled, an attacker could possibly exploit these to cause a denial of

service via application crash, or potentially execute arbitrary code with

the privileges of the user invoking Thunderbird. (CVE-2013-1739,

CVE-2013-5590, CVE-2013-5591)

Jordi Chancel discovered that HTML select elements could display arbitrary

content. If a user had scripting enabled, an attacker could potentially

exploit this to conduct URL spoofing or clickjacking attacks.

(CVE-2013-5593)

Abhishek Arya discovered a crash when processing XSLT data in some

circumstances. If a user had scripting enabled, an attacker could

potentially exploit this to execute arbitrary code with the privileges

of the user in...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  thunderbird                     1:24.1.0+build1-0ubuntu0.13.10.1

Ubuntu 13.04:
  thunderbird                     1:24.1.0+build1-0ubuntu0.13.04.1

Ubuntu 12.10:
  thunderbird                     1:24.1.0+build1-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  thunderbird                     1:24.1.0+build1-0ubuntu0.12.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2010-1

CVE-2013-1739, CVE-2013-5590, CVE-2013-5591, CVE-2013-5593,

CVE-2013-5595, CVE-2013-5596, CVE-2013-5597, CVE-2013-5599,

CVE-2013-5600, CVE-2013-5601, CVE-2013-5602, CVE-2013-5603,

CVE-2013-5604, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1245422

October 31, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.