Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 16.04 LTS: USN-3073-1 Critical: Thunderbird Memory Safety Threat

ubuntu
Calendar Grey September 22, 2016
Scroller Ubuntu
Ubuntu Security Announcement USN-3073-1 pertains to vulnerabilities in Thunderbird that might enable code execution or result in application crashes.
Thunderbird could be made to crash or run programs as your login if it opened a malicious message.

Summary

Thunderbird could be made to crash or run programs as your login if it

opened a malicious message.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Christian Holler, Carsten Book, Gary Kwong, Jesse Ruderman, Andrew

McCreight, and Phil Ringnalda discovered multiple memory safety issues in

Thunderbird. If a user were tricked in to opening a specially crafted

message, an attacker could potentially exploit these to cause a denial of

service via application crash, or execute arbitrary code. (CVE-2016-2836)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  thunderbird                     1:45.3.0+build1-0ubuntu0.16.04.2

Ubuntu 14.04 LTS:
  thunderbird                     1:45.3.0+build1-0ubuntu0.14.04.4

Ubuntu 12.04 LTS:
  thunderbird                     1:45.3.0+build1-0ubuntu0.12.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3073-1

CVE-2016-2836

Severity
critical
Lowest
Low
Medium
High
Critical

September 22, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.