Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 439
Alerts This Week
Warning Icon 1 439

Ubuntu 13.10: USN-2032-1 Critical: Thunderbird Denial Of Service

ubuntu
Calendar Grey November 21, 2013
Scroller Ubuntu
Several vulnerabilities addressed in Thunderbird patches for different Ubuntu versions, immediate system upgrade advised.
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Multiple security issues were discovered in Thunderbird. If a user were

tricked into connecting to a malicious server, an attacker could possibly

exploit these to cause a denial of service via application crash,

potentially execute arbitrary code, or lead to information disclosure.

(CVE-2013-1741, CVE-2013-2566, CVE-2013-5605, CVE-2013-5607)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  thunderbird                     1:24.1.1+build1-0ubuntu0.13.10.1

Ubuntu 13.04:
  thunderbird                     1:24.1.1+build1-0ubuntu0.13.04.1

Ubuntu 12.10:
  thunderbird                     1:24.1.1+build1-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  thunderbird                     1:24.1.1+build1-0ubuntu0.12.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2032-1

CVE-2013-1741, CVE-2013-2566, CVE-2013-5605, CVE-2013-5607,

https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1253027

Severity
critical
Lowest
Low
Medium
High
Critical

November 21, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.