Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Ubuntu 16.10: USN-3112-1 Moderate: Thunderbird DoS Risks Addressed

ubuntu
Calendar Grey October 27, 2016
Scroller Ubuntu
Address potential vulnerabilities by applying Thunderbird patches on Ubuntu versions ranging from 12.04 to 16.10 in accordance with USN-3112-1 guidelines.
Several security issues were fixed in Thunderbird.

Summary

Several security issues were fixed in Thunderbird.

Software Description:

- thunderbird: Mozilla Open Source mail and newsgroup client

Details:

Catalin Dumitru discovered that URLs of resources loaded after a

navigation start could be leaked to the following page via the Resource

Timing API. If a user were tricked in to opening a specially crafted

website in a browsing context, an attacker could potentially exploit this

to obtain sensitive information. (CVE-2016-5250)

Christoph Diehl, Andrew McCreight, Dan Minor, Byron Campen, Jon Coppeard,

Steve Fink, Tyson Smith, and Carsten Book discovered multiple memory

safety issues in Thunderbird. If a user were tricked in to opening a

specially crafted message, an attacker could potentially exploit these to

cause a denial of service via application crash, or execute arbitrary

code. (CVE-2016-5257)

Atte Kettunen discovered a heap buffer overflow during text conversion

with some unicode characters. If a user were tri...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
  thunderbird                     1:45.4.0+build1-0ubuntu0.16.10.1

Ubuntu 16.04 LTS:
  thunderbird                     1:45.4.0+build1-0ubuntu0.16.04.1

Ubuntu 14.04 LTS:
  thunderbird                     1:45.4.0+build1-0ubuntu0.14.04.1

Ubuntu 12.04 LTS:
  thunderbird                     1:45.4.0+build1-0ubuntu0.12.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3112-1

CVE-2016-5250, CVE-2016-5257, CVE-2016-5270, CVE-2016-5272,

CVE-2016-5274, CVE-2016-5276, CVE-2016-5277, CVE-2016-5278,

CVE-2016-5280, CVE-2016-5281, CVE-2016-5284

Severity
important
Lowest
Low
Medium
High
Critical

October 27, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.