An out-of-bounds write was discovered in Thunderbird, which could be triggered via a malformed email message. For the oldstable distribution (buster), this problem has been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5086-1
The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2011-1508 https://access.redhat.com/errata/RHSA-2011:1508.html The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: i386: cyrus-imapd-2.3.7-12.0.1.el5_7.2.i386.rpm cyrus-imapd-devel-2.3.7-12.0.1.el5_7.2.i386.rpm cyrus-imapd-perl-2.3.7-12.0.1.el5_7.2.i386.rpm cyrus-imapd-utils-2.3.7-12.0.1.el5_7.2.i386.rpm x86_64: cyrus-imapd-2.3.7-12.0.1.el5_7.2.x86_64.rpm cyrus-imapd-devel-2.3.7-12.0.1.el5_7.2.i386.rpm cyrus-imapd-devel-2.3.7-12.0.1.el5_7.2.x86_64.rpm cyrus-imapd-perl-2.3.7-12.0.1.el5_7.2.x86_64.rpm cyrus-imapd-utils-2.3.7-12.0.1.el5_7.2.x86_64.rpm ia64: cyrus-imapd-2.3.7-12.0.1.el5_7.2.ia64.rpm cyrus-imapd-devel-2.3.7-12.0.1.el5_7.2.ia64.rpm cyrus-imapd-perl-2.3.7-12.0.1.el5_7.2.ia64.rpm cyrus-imapd-utils-2.3.7-12.0.1.el5_7.2.ia64.rpm SRPMS: https://oss.oracle.com:443/ol5/SRPMS-updates/cyrus-imapd-2.3.7-12.0.1.el5_7.2.src.rpm Description of changes: [2.3.7-12.0.1.el5_7.2] - Enabled lm_sensors-devel build dependency for x86 and x86_64 only [2.3.7-12.2] - fix CVE-2011-3481: NULL pointer dereference via crafted References header in email (#738391) - fix CVE-2011-3372: nntpd authentication bypass (#740822) . Oracle Linux 5 has been issued a significant security patch for cyrus, addressing severe vulnerabilities along with key rpm updates.. Oracle Linux,Cyrus IMAP,Security Update,ELSA-2011-1508,Threat Fixes. . Severity: Important. LinuxSecurity.com Team
Sergey Kononenko and Eugene Bujak discovered that Exim did not correctlytruncate string expansions. A remote attacker could send specially craftedemail traffic to run arbitrary code as the Exim user, which could alsolead to root privileges. [More...]. ==========================================================Ubuntu Security Notice USN-1032-1 December 11, 2010 exim4 vulnerability CVE-2010-4344 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 9.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: exim4-daemon-custom 4.60-3ubuntu3.2 exim4-daemon-heavy 4.60-3ubuntu3.2 exim4-daemon-light 4.60-3ubuntu3.2 Ubuntu 8.04 LTS: exim4-daemon-custom 4.69-2ubuntu0.2 exim4-daemon-heavy 4.69-2ubuntu0.2 exim4-daemon-light 4.69-2ubuntu0.2 Ubuntu 9.10: exim4-daemon-custom 4.69-11ubuntu4.1 exim4-daemon-heavy 4.69-11ubuntu4.1 exim4-daemon-light 4.69-11ubuntu4.1 In general, a standard system update will make all the necessary changes. Details follow: Sergey Kononenko and Eugene Bujak discovered that Exim did not correctly truncate string expansions. A remote attacker could send specially crafted email traffic to run arbitrary code as the Exim user, which could also lead to root privileges. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 326950 65e62a09e080c821e398a63cf92a6d1f Size/MD5: 1710 56df0b8c8d370e21120658155de9c3fa Size/MD5: 2022260 5f8e5834c648ac9a62bb8ab6ad2a6227 Architecture independent packages: Size/MD5: 263080 359ce4b2bd41c72718c137e465342696 Size/MD5: 1580 feabe1136ff1d77db3bf15a3d0e95d23 amd64 architecture (Athlon64, Opteron, EM64TXeon): Size/MD5: 876940 341ab7347734de16c49182757d15e209 Size/MD5: 468624 23925ea701e015f23b5252e6023241a8 Size/MD5: 414586 16f48b776d5757043f167239fe931fe0 Size/MD5: 86502 2dd6d4b0fe218b3e6416ae03e13540f4 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 873970 d7227fdecda4f57c4f0a46895f0047fe Size/MD5: 423706 8a7293ab75f5ffff0029a7e60294d6e8 Size/MD5: 374388 b0cbe933f4adc32b6b0228d3819f53cf Size/MD5: 81898 d1151fdb573847abf6ef7a2c476dec46 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 883758 1973a2fe4863ed692b22d41a97d4d3f7 Size/MD5: 469898 c81c330d96ce8f8e9fbb3611ddae9451 Size/MD5: 416324 1adda1365428df3dda3ad2eca06a5b0d Size/MD5: 88496 3ddbbdfcad0dc9c4ea0cc1257a66f806 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 874312 87893cdf1323bc6271da745379efeb63 Size/MD5: 444438 8d88c67448778b105336151ffcf9b9cc Size/MD5: 394234 8ea9e87dbb5bc7b8e34b7e39be3f14dd Size/MD5: 83748 6b14d9e0a764114fdddd73e9bf518acc Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 542324 684652aca4ddc876130dc1e747abe639 Size/MD5: 1946 b6f0b4b89968ea9f8baaf398b3c40305 Size/MD5: 1659309 f0176239d54546526f519e266182c019 Architecture independent packages: Size/MD5: 310444 b27c6deeab84c0d9d1834975de452079 Size/MD5: 6356 e3e360d03367ada5058186fda42bf412 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 985396 646127f389dc10c56f9ce9b76288ea0e Size/MD5: 787748 5bf7ad817c0b96661433613c65dc2541 Size/MD5: 496550 e309c2170877949d51f3c9da12d1606b Size/MD5: 701732 ace3c153ef2e6c00e578458c6667bd98 Size/MD5: 442708 c2e54c2f539e85d48b40123540aec66c Size/MD5: 267568 4ab6961efc6909ecc21a0dc11524e355 Size/MD5: 683360f916ca937aa199124a37e5dcbf901d3 Size/MD5: 100648 30dd3dcc34805edbeb843a2e1a0419e4 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 981574 c6bdac374c384e75709ddbc4584c78a0 Size/MD5: 748140 89cfe95a5d9a006a60a4e0c93a36f176 Size/MD5: 467732 d3d1784cfb941570e62b348cbf18c634 Size/MD5: 667830 2ad120163463491c374bc4732cf30fa3 Size/MD5: 416776 54e80325909177eff906dd468cc2ab34 Size/MD5: 260684 9ec594f594d7de456edb7883a4db11c0 Size/MD5: 68340 bb7173daff16f19ccc5a50359f74cfaa Size/MD5: 96086 127416ada041e7074a153e856cafb938 lpia architecture (Low Power Intel Architecture): Size/MD5: 982010 c14a5270224544ce1b964469607002a0 Size/MD5: 762118 3ac2e6594a46175328ea3a0a41454f3a Size/MD5: 465198 b68b7099bbd223a28e2b244629ed5ceb Size/MD5: 678182 0bcb9cbb5eca98a174b547d1b815770c Size/MD5: 414510 c4d1073ae10ac0f94a74aa49bfcc9e98 Size/MD5: 262380 9898befd0cc82b2dcbc196f9682ffb2a Size/MD5: 68352 028371d72c5e06a549c394870ef67b89 Size/MD5: 96048 799182419e8721e485485747541a85f4 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 985382 48ddd029fda6f3a39640ce0a45b82028 Size/MD5: 786138 0876d0748141809d4ff6429457165563 Size/MD5: 513280 2db5199ab6423edebdba511551db8b62 Size/MD5: 703960 5cc4faeaa585d8941cf6214318bd5b17 Size/MD5: 455878 50c08967a3ec824e8645e0a35541456a Size/MD5: 275044 360d13462ca6e826ac875ee22b1a27e1 Size/MD5: 68350 d237b34a403174d6d6d934f2162dfc6d Size/MD5: 104764 ac28a25431d743ed4ea171e7d1ce99c2 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 982370 3fb20f69090a7709195266af3a15fe2e Size/MD5: 741860 f672767f502724a3f494f175277a2b60 Size/MD5: 479786 761c69d7c6464768432b826f0a064be3 Size/MD5: 662310 04e260bc4f8b1f247b9fd215b990eb17 Size/MD5: 426994 b72924c18424294579f5f57fa8c2013f Size/MD5: 260010 3b3feefc54a37292e2e1a50b90901396 Size/MD5: 68346 7fc9cea90f650e451123edf893d67d95 Size/MD5: 97782 6d1b8efca2ba6ddacf715d3681b78373 Updated packages for Ubuntu 9.10: Source archives: Size/MD5: 552585 11dba71d2f51a531dfbe030149ac2616 Size/MD5: 2371 e11ceeebee781339679135bce2abe397 Size/MD5: 1659309 f0176239d54546526f519e266182c019 Architecture independent packages: Size/MD5: 371854 52414ba2baf1c4a04eae981277055955 Size/MD5: 7950 3dc329a42c7277a881e11dc67d6ec26a amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 997338 60d6d9230266bef5252032836d759efe Size/MD5: 838022 6caa8c44754e391ce183b3bacdbd9498 Size/MD5: 544194 3c261ca58188fd58fa604a0cdaadcfa9 Size/MD5: 742158 8bdae915a7843290a9c18f37e11f753d Size/MD5: 488240 d7e86dd8164f4e02e4c1744e53600ebf Size/MD5: 280102 f561098ed480b00632f8ae25bf2e95f2 Size/MD5: 72056 65d2f1b2b7aca4685b485bee6e8e40ab Size/MD5: 107892 f4c6f0de550ba029169f02bc66f2d602 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 994680 4a7cf2144d4d02286cec9575c929e136 Size/MD5: 798296 946a4c06e065e7e4f6bc340d03426719 Size/MD5: 514902 11e0fbb495e2ad630e548e2a3e0d5f07 Size/MD5: 707224 ecb77bc0a1a59ab28aaa46492ee5dc00 Size/MD5: 462410 f0ff9f7d0332bc49f50982a1ad7f8d78 Size/MD5: 274384 d682d6b5f5889af154176df6c120c160 Size/MD5: 72042 96ad9118dffa077ac2dd4fd82cbefecc Size/MD5: 103934 c99c724eead0d85e92a43706f858543c armel architecture (ARM Architecture): Size/MD5: 998324 1f6d71876f8f663ebe464a94873fe9e1 Size/MD5: 800678 9d213fc523dad77ed32b116091247124 Size/MD5: 492850 141ddaaa9408c6966545954f3fd711b2 Size/MD5: 708006 eeb57c0432e924fde0475aa33be7c16a Size/MD5: 442464 901d8991e58bb7eb752e1ddc002a36c0 Size/MD5: 276866 479fb0f71294d8edf96c1ee112b71a7b Size/MD5: 72038 a57070daa19f52edf185b358c1acb9cf Size/MD5: 101966 4e01888c6a9ed05aed78f404e5c2c2e5 lpia architecture (Low Power Intel Architecture): Size/MD5: 994470 2ffebb741e1f8b60fe4f2591faf69ba5 Size/MD5: 809464 bad54d53cd66ff492e617e6a5fe747b4 Size/MD5: 513420 944dfbf91d1d47570cf4beac113dbf1e Size/MD5: 718372 24ae980ea40a6cce6c3bc6e5cef59cc5 Size/MD5: 460068 b9824d586d4a1dbf922301ee5143830a Size/MD5: 275540 99bcc98393cfd51ea586cd4e6005600a Size/MD5: 72054 b79b154eb510cfeb1e8a716b2c00fad2 Size/MD5: 103444 d4c9bcd0086a036a112aaee566b97c99 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 997714 691a23f30a287c89b93e867e77ebcc38 Size/MD5: 860134 beb27c57066d52542399f37d6199d2d0 Size/MD5: 559436 cad28e7e802bdf7e4765ccb069cbb934 Size/MD5: 765252 46cc4f2a70730c889296ee8b2200d900 Size/MD5: 500176 ca794eea0dc57873e58f3fe04d4d063a Size/MD5: 286262 ff8331c62147bcfa31480eca018cb268 Size/MD5: 72058 c71d83c209896a52e214e876aa976345 Size/MD5: 108948 02416f3e1f7e124a41bf8c5d7dd5b9e6 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 996654 8aed2bd56548d55bd4c0f66e3cefa235 Size/MD5: 802528 60a2db91419181f6ebc41605d78b2170 Size/MD5: 540910 4be026ab559a35d48d36489883bfd293 Size/MD5: 713966 929872a08329c71a46b99645d3c3d941 Size/MD5: 485902 b57f4247f29aee0ca1ee4847cb091c43 Size/MD5: 274414 44e8af10162fdb0ce7973e07f7e661e5 Size/MD5: 72054 c332909031c776ebc9a7d21a23770fe6 Size/MD5: 105590 a5d4bc7bfeadd3206fd2f61b7f38a974 . Enhance the security of your Ubuntu machines by patching the Exim vulnerability that permits code execution through specially designed email messages.. EximVulnerability, Ubuntu Security, Remote Code Risk. . Severity: Critical. LinuxSecurity.com Team
Various flaws were discovered in the layout and JavaScript engines. By tricking a user into opening a malicious email, an attacker could execute arbitrary code with the user's privileges. Please note that JavaScript is disabled by default for emails, and it is not recommended to enable it. . =========================================================== Ubuntu Security Notice USN-503-1 August 24, 2007 mozilla-thunderbird vulnerabilities CVE-2007-3670, CVE-2007-3734, CVE-2007-3735, CVE-2007-3844, CVE-2007-3845 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: mozilla-thunderbird 1.5.0.13-0ubuntu0.6.06 Ubuntu 6.10: mozilla-thunderbird 1.5.0.13-0ubuntu0.6.10 Ubuntu 7.04: mozilla-thunderbird 1.5.0.13-0ubuntu0.7.04 After a standard system upgrade you need to restart Thunderbird to effect the necessary changes. Details follow: Various flaws were discovered in the layout and JavaScript engines. By tricking a user into opening a malicious email, an attacker could execute arbitrary code with the user's privileges. Please note that JavaScript is disabled by default for emails, and it is not recommended to enable it. (CVE-2007-3734, CVE-2007-3735, CVE-2007-3844) Jesper Johansson discovered that spaces and double-quotes were not correctly handled when launching external programs. In rare configurations, after tricking a user into opening a malicious email, an attacker could execute helpers with arbitrary arguments with the user's privileges. (CVE-2007-3670, CVE-2007-3845) Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 455132 d8467a49fa9749a12d06330212cb0fa5 Size/MD5: 1603 ec53fcdf9b56d3f3d46266c249ebd597 Size/MD5: 36080566 62b37f8d4777f305146623d7437e3ccd amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 3586642 2c36816d1f7a03ef145ce5d30e60d418 Size/MD5: 194370 cf8d5d4dfb807f09bddaa39c3787de7a Size/MD5: 59612 752bdd32f219cbc227d5481d217dddcb Size/MD5: 12095766 6a8064a3040e2ceba8d23d4215511503 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 3578708 fa6953c372876d3475a57fe7698f0efb Size/MD5: 187744 53f0bec282e4901d673d4052b9cf76c0 Size/MD5: 55134 ccd78eca24e17b788416d06b5cd970b9 Size/MD5: 10369278 597f681fcf328b6e17bb9ba00301b238 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 3584414 956c1a25ec9285efb111ae8001c14fff Size/MD5: 191098 ebb6fa00a8ba29a16b45266b9be70822 Size/MD5: 58742 8aae905e454ae490b27c1d35f717235a Size/MD5: 11650578 2cc2f06a14cf7c6b77d4f913ef57ac34 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 3580718 d5d9508759e3c19cd6b1c9a02ca91adc Size/MD5: 188542 5a4ee0e188ef31a759ab183d833d4685 Size/MD5: 56626 3dbbd7cd060a11112a5fd1a7fd23cd35 Size/MD5: 10844686 de165e9bb539e3ae662676a4ca3029e7 Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 455992 38afdbcb0d339c8ee3b1cab8f33b6fa1 Size/MD5: 1601 0a8019db6f355e5ccc2b5eb6a704a73f Size/MD5: 36080566 62b37f8d4777f305146623d7437e3ccd amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 3586466 426017c63f2dc362c8c5a664b5a906b1 Size/MD5: 194496 4c7c6349b9829de611db2e8222f9150a Size/MD5: 59626 f5d323ecafeae46ae34cac71706d99d5 Size/MD5: 12091050 61350cf3dc12e29dbac243fc9e911be5 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 3582338 319eb753f7570f045e9de39795bf0646 Size/MD5: 189152687f5583b93df5db616ab8fe7f8eb3e8 Size/MD5: 56258 6cfcdbb6d930e8a4f535fb5ca5d476f0 Size/MD5: 10829290 a3c2ca0abeccef3570fccacd3a05c60e powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 3584542 717064f808322f7ca11bc22551ee2127 Size/MD5: 191580 3fd254e0d0ec073832e01af8db9656e7 Size/MD5: 59334 3f0c56850ed5f96888c3feffc75fd96b Size/MD5: 11779014 0b7e4785c95d1fd0b8c16bac50686349 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 3580676 e5ecded833e695d40fb0ae30b84ca685 Size/MD5: 188984 367b43b2719cf830d1a318de5315bf46 Size/MD5: 56682 46103432a77551215c77c935d08e6b42 Size/MD5: 11041104 984bf1c75968dd40149956254f94fabb Updated packages for Ubuntu 7.04: Source archives: Size/MD5: 126635 4c85da89acdf347587cfcfb3d9433304 Size/MD5: 1601 d306cbba411cc32f7f579acfb559c9b0 Size/MD5: 36080566 62b37f8d4777f305146623d7437e3ccd amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 3587044 0780090e7e421d87ab8bcc5137d2922c Size/MD5: 195006 415f02a983531cd65f0f15a895f1e0d0 Size/MD5: 60144 74c446643a9674a3dd3c1a2f04861c8e Size/MD5: 12187948 f85553218e76dbb5178358b2cf0b65d9 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 3583270 7657f360e3b57b77d7955051e435175b Size/MD5: 189648 20ee57f83d22e2b39e4d0d9d71ac7065 Size/MD5: 56760 58a55ba7a1f760ca76fd3b9142ab42a0 Size/MD5: 10916670 f13212b9d47949ed8b854348e14dfed2 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 3587820 ece8b66570abedc631dd58b37b586ab7 Size/MD5: 193120 c472b0175bea62f0d228770c0ab9e261 Size/MD5: 60128 71c1d1364c88ae38f43953e51b06a72f Size/MD5: 12131446 829c93637e9e61864e5303adb36a602f sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 3582290c14265f81e5fbc21022e0f91a6b12603 Size/MD5: 189470 c47268c61b56f5bebf845d06585a9bfa Size/MD5: 57188 511ca6c3e342af386da76fab926f697f Size/MD5: 11143012 43b4637793f6994d92e8bdff215cb183 . Ubuntu Security Notice USN-504-2 highlights severe vulnerabilities found in Firefox that impact multiple versions.. Thunderbird Security, Code Execution Risk, Email Exploits, Ubuntu Advisory. . Severity: Critical. LinuxSecurity.com Team
Moderate: thunderbird security update. Date: Thu, 19 Jul 2007 16:04:47 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for thunderbird on SL5.x, SL4.x, SL3,x i386/x86_64 Comments: To:
Pine versions 4.21 and before contain a buffer overflow vulnerability which allows a remote user to execute arbitrary code on the local client by the sending of a special-crafted email message.. Pine versions 4.21 and before contain a buffer overflow vulnerability which allows a remote user to execute arbitrary code on the local client by the sending of a special-crafted email message. The overflow occursduring the periodic "new mail" checking of an open folder. By upgrading to Pine 4.30, users can fix this problem. New pine.tgz and imapd.tgz packages are available for users of Slackware Linux 7.0, 7.1, and -current. ================================================ Pine 4.30 AVAILABLE - (n1/pine.tgz, n1/imapd.tgz) ================================================ The buffer overflow vulnerability that affects Pine 4.21 and earlier can be fixed by upgrading to the new Pine 4.30 packages. The new pine.tgz and imapd.tgz are available in the -current branch: For verification purposes, we provide the following checksums: 16-bit "sum" checksum: 58447 1475 n1/pine.tgz 11458 654 n1/imapd.tgz 128-bit MD5 message digest: 2f7cdbca84e9d3473c74c6cf6ed24b79 n1/pine.tgz 81a5c7373e30357679fe613e38e07a01 n1/imapd.tgz INSTALLATION INSTRUCTIONS FOR THE pine.tgz PACKAGE: --------------------------------------------------- Make sure that no users have Pine running, then issue this command: # upgradepkg pine.tgz INSTALLATION INSTRUCTIONS FOR THE imapd.tgz PACKAGE: --------------------------------------------------- The IMAP and POP3 servers provided by the imapd.tgz package run from inetd. Make sure they are not running. This can be easily accomplished by dropping the machine into single user mode: # telinit 1 Then upgrade the imapd.tgz package: # upgradepkg imapd.tgz Remember, it's also a good idea to backup configuration files before upgrading packages. - Slackware Linux Security Team The Slackware LinuxProject . Different versions of Oak before 3.14 contain a serious security flaw that facilitates unauthorized code execution through specially designed messages. Immediate revisions are crucial!. Pine Update, Slackware Security, Remote Code Execution, Email Exploits, Buffer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.