Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu: 13.10 Advisory 2119-1 Critical: ThunderBird DDoS Vulnerabilities

ubuntu
Calendar Grey February 19, 2014
Scroller Ubuntu
Various vulnerabilities detected in Thunderbird on Ubuntu may result in service interruptions and unauthorized code execution.
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Christian Holler, Terrence Cole, Jesse Ruderman, Gary Kwong, Eric

Rescorla, Jonathan Kew, Dan Gohman, Ryan VanderMeulen and Sotaro Ikeda

discovered multiple memory safety issues in Thunderbird. If a user were

tricked in to opening a specially crafted message with scripting enabled,

an attacker could potentially exploit these to cause a denial of service

via application crash, or execute arbitrary code with the privileges of

the user invoking Thunderbird. (CVE-2014-1477)

Cody Crews discovered a method to bypass System Only Wrappers. If a user

had enabled scripting, an attacker could potentially exploit this to steal

confidential data or execute code with the privileges of the user invoking

Thunderbird. (CVE-2014-1479)

Fredrik Lönnqvist discovered a use-after-free in Thunderbird. If a user

had enabled scripting, an ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  thunderbird                     1:24.3.0+build2-0ubuntu0.13.10.1

Ubuntu 12.10:
  thunderbird                     1:24.3.0+build2-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  thunderbird                     1:24.3.0+build2-0ubuntu0.12.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2119-1

CVE-2013-6674, CVE-2014-1477, CVE-2014-1479, CVE-2014-1481,

CVE-2014-1482, CVE-2014-1486, CVE-2014-1487, CVE-2014-1490,

CVE-2014-1491, https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1274894

Severity
critical
Lowest
Low
Medium
High
Critical

February 19, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.