Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
200

Scientific Linux: CVE-2011-2982 Critical: Thunderbird Remote Code Execution

Critical: thunderbird security update. Date: Wed, 17 Aug 2011 11:25:51 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Critical: thunderbird on SL6.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." MIME-Version: 1.0 Synopsis: Critical: thunderbird security update Issue Date: 2011-08-16 CVE Numbers: CVE-2011-2982 CVE-2011-0084 CVE-2011-2378 Mozilla Thunderbird is a standalone mail and newsgroup client. Several flaws were found in the processing of malformed HTML content. Malicious HTML content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2011-2982) A dangling pointer flaw was found in the Thunderbird Scalable Vector Graphics (SVG) text manipulation routine. An HTML mail message containing a malicious SVG image could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2011-0084) A dangling pointer flaw was found in the way Thunderbird handled a certain Document Object Model (DOM) element. An HTML mail message containing malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2011-2378) All Thunderbird users should upgrade to this updated package, which resolves these issues. All running instances of Thunderbird must be restarted for the update to take effect. SL6: i386 thunderbird-3.1.12-1.el6_1.i686.rpm x86_64 thunderbird-3.1.12-1.el6_1.x86_64.rpm - Scientific Linux Development Team . Essential security patch for Thunderbird rectifies vulnerabilities impacting users; prompt upgrade advised to mitigate risks.. Thunderbird Security Update, Scientific Linux Update, Critical Security Advisory, Remote Code Execution, HTML Flaws. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 17, 2011 Critical Scientific Linux
98

Red Hat: RHSA-2011:1165-01 Critical: Thunderbird HTML/JS Issues

An updated thunderbird package that fixes several security issues is now available for Red Hat Enterprise Linux 4 and 5. The Red Hat Security Response Team has rated this update as having critical [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Critical: thunderbird security update Advisory ID: RHSA-2011:1165-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:1165.html Issue date: 2011-08-16 CVE Names: CVE-2011-2982 CVE-2011-2983 ==================================================================== 1. Summary: An updated thunderbird package that fixes several security issues is now available for Red Hat Enterprise Linux 4 and 5. The Red Hat Security Response Team has rated this update as having critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: RHEL Optional Productivity Applications (v. 5 server) - i386, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Description: Mozilla Thunderbird is a standalone mail and newsgroup client. Several flaws were found in the processing of malformed HTML content. Malicious HTML content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2011-2982) A flaw was found in the way Thunderbird handled malformed JavaScript. Malicious content could cause Thunderbird to access already freed memory, causing Thunderbird to crash or, potentially, execute arbitrary code with theprivileges of the user running Thunderbird. (CVE-2011-2983) Note: This update disables support for Scalable Vector Graphics (SVG) images in Thunderbird on Red Hat Enterprise Linux 5. All Thunderbird users should upgrade to this updated package, which resolves these issues. All running instances of Thunderbird must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 730518 - CVE-2011-2982 Mozilla: Miscellaneous memory safety hazards 730523 - CVE-2011-2983 Mozilla: Private data leakage using RegExp.input 6. Package List: Red Hat Enterprise Linux AS version 4: Source: i386: thunderbird-1.5.0.12-40.el4.i386.rpm thunderbird-debuginfo-1.5.0.12-40.el4.i386.rpm ia64: thunderbird-1.5.0.12-40.el4.ia64.rpm thunderbird-debuginfo-1.5.0.12-40.el4.ia64.rpm ppc: thunderbird-1.5.0.12-40.el4.ppc.rpm thunderbird-debuginfo-1.5.0.12-40.el4.ppc.rpm s390: thunderbird-1.5.0.12-40.el4.s390.rpm thunderbird-debuginfo-1.5.0.12-40.el4.s390.rpm s390x: thunderbird-1.5.0.12-40.el4.s390x.rpm thunderbird-debuginfo-1.5.0.12-40.el4.s390x.rpm x86_64: thunderbird-1.5.0.12-40.el4.x86_64.rpm thunderbird-debuginfo-1.5.0.12-40.el4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: thunderbird-1.5.0.12-40.el4.i386.rpm thunderbird-debuginfo-1.5.0.12-40.el4.i386.rpm x86_64: thunderbird-1.5.0.12-40.el4.x86_64.rpm thunderbird-debuginfo-1.5.0.12-40.el4.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: thunderbird-1.5.0.12-40.el4.i386.rpm thunderbird-debuginfo-1.5.0.12-40.el4.i386.rpm ia64: thunderbird-1.5.0.12-40.el4.ia64.rpm thunderbird-debuginfo-1.5.0.12-40.el4.ia64.rpm x86_64: thunderbird-1.5.0.12-40.el4.x86_64.rpm thunderbird-debuginfo-1.5.0.12-40.el4.x86_64.rpm RedHat Enterprise Linux WS version 4: Source: i386: thunderbird-1.5.0.12-40.el4.i386.rpm thunderbird-debuginfo-1.5.0.12-40.el4.i386.rpm ia64: thunderbird-1.5.0.12-40.el4.ia64.rpm thunderbird-debuginfo-1.5.0.12-40.el4.ia64.rpm x86_64: thunderbird-1.5.0.12-40.el4.x86_64.rpm thunderbird-debuginfo-1.5.0.12-40.el4.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: thunderbird-2.0.0.24-21.el5.i386.rpm thunderbird-debuginfo-2.0.0.24-21.el5.i386.rpm x86_64: thunderbird-2.0.0.24-21.el5.x86_64.rpm thunderbird-debuginfo-2.0.0.24-21.el5.x86_64.rpm RHEL Optional Productivity Applications (v. 5 server): Source: i386: thunderbird-2.0.0.24-21.el5.i386.rpm thunderbird-debuginfo-2.0.0.24-21.el5.i386.rpm x86_64: thunderbird-2.0.0.24-21.el5.x86_64.rpm thunderbird-debuginfo-2.0.0.24-21.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2011-2982 https://access.redhat.com/security/cve/CVE-2011-2983 https://access.redhat.com/security/updates/classification/#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2011 Red Hat, Inc. . Update Thunderbird on Red Hat Linux versions 4 and 5 to rectify severe vulnerabilities related to HTML and JavaScript interpretation.. Red Hat Enterprise Linux, Thunderbird Security Update, Mozilla Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 16, 2011 Critical Red Hat
89

Fedora 9 Update: Security Advisory for Thunderbird HTML Vulnerability

Several flaws were found in the processing of malformed HTML mail content. An HTML mail message containing malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code as the user running Thunderbird. (CVE-2009-0040, CVE-2009-0352, CVE-2009-0353, CVE-2009-0772, CVE-2009-0774, CVE-2009-0775) Several flaws were found in the way malformed content was processed. An HTML mail message containing specially-crafted content could potentially trick a Thunderbird user into surrendering sensitive information. (CVE-2009-0355, CVE-2009-0776) Note: JavaScript support is disabled by default in Thunderbird. None of the above issues are exploitable unless JavaScript is enabled.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-2884 2009-03-21 00:48:58 --------------------------------------------------------------------------------Name : thunderbird Product : Fedora 9 Version : 2.0.0.21 Release : 1.fc9 URL : https://wiki.mozilla.org/Thunderbird:Home_Page Summary : Mozilla Thunderbird mail/newsgroup client Description : Mozilla Thunderbird is a standalone mail and newsgroup client. --------------------------------------------------------------------------------Update Information: Several flaws were found in the processing of malformed HTML mail content. An HTML mail message containing malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code as the user running Thunderbird. (CVE-2009-0040, CVE-2009-0352, CVE-2009-0353, CVE-2009-0772, CVE-2009-0774, CVE-2009-0775) Several flaws were found in the way malformed content was processed. An HTML mail message containing specially-crafted content could potentially trick a Thunderbird user into surrendering sensitive information. (CVE-2009-0355, CVE-2009-0776) Note: JavaScript support is disabled by default in Thunderbird. None of the above issues are exploitable unless JavaScript isenabled. --------------------------------------------------------------------------------ChangeLog: * Fri Mar 20 2009 Christopher Aillon - 2.0.0.21-1 - Update to 2.0.0.21 * Wed Jan 7 2009 Christopher Aillon - 2.0.0.19-2 - Disable the crash dialog * Mon Jan 5 2009 Christopher Aillon 2.0.0.19-1 - Update to 2.0.0.19 * Wed Nov 19 2008 Christopher Aillon 2.0.0.18-1 - Update to 2.0.0.18 * Thu Oct 9 2008 Christopher Aillon 2.0.0.17-1 - Update to 2.0.0.17 * Wed Jul 23 2008 Christopher Aillon 2.0.0.16-1 - Update to 2.0.0.16 --------------------------------------------------------------------------------References: [ 1 ] Bug #486355 - CVE-2009-0040 libpng arbitrary free() flaw https://bugzilla.redhat.com/show_bug.cgi?id=486355 [ 2 ] Bug #483139 - CVE-2009-0352 Firefox layout crashes with evidence of memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=483139 [ 3 ] Bug #483141 - CVE-2009-0353 Firefox javascript crashes with evidence of memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=483141 [ 4 ] Bug #483143 - CVE-2009-0355 Firefox local file stealing with SessionStore https://bugzilla.redhat.com/show_bug.cgi?id=483143 [ 5 ] Bug #488273 - CVE-2009-0772 Firefox 2 and 3 - Layout engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=488273 [ 6 ] Bug #488283 - CVE-2009-0774 Firefox 2 and 3 crashes in the JavaScript engine https://bugzilla.redhat.com/show_bug.cgi?id=488283 [ 7 ] Bug #488287 - CVE-2009-0775 Firefox XUL Linked Clones Double Free Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=488287 [ 8 ] Bug #488290 - CVE-2009-0776 Firefox XML data theft via RDFXMLDataSource and cross-domain redirect https://bugzilla.redhat.com/show_bug.cgi?id=488290 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update thunderbird' at the command line. For moreinformation, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Thunderbird update for Fedora 9 has been released to fix vulnerabilities in HTML processing that could permit the execution of harmful content by malicious actors.. thunderbird update,fedora security,html flaws,mail client threat. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 20, 2009 Critical Fedora
89

Fedora 7: FEDORA-2008-2118 Critical: Thunderbird HTML Flaws

Several flaws were found in the way Thunderbird processed certain malformed HTML mail content. . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2008-2118 2008-02-28 21:16:44 --------------------------------------------------------------------------------Name : thunderbird Product : Fedora 7 Version : 2.0.0.12 Release : 1.fc7 URL : https://wiki.mozilla.org/Thunderbird:Home_Page Summary : Mozilla Thunderbird mail/newsgroup client Description : Mozilla Thunderbird is a standalone mail and newsgroup client. --------------------------------------------------------------------------------Update Information: Mozilla Thunderbird is a standalone mail and newsgroup client. Several flaws were found in the way Thunderbird processed certain malformed HTML mail content. A HTML mail message containing malicious content could cause Thunderbird to crash, or potentially execute arbitrary code as the user running Thunderbird. (CVE-2008-0412, CVE-2008-0413, CVE-2008-0415, CVE-2008-0419) Several flaws were found in the way Thunderbird displayed malformed HTML mail content. A HTML mail message containing specially-crafted content could trick a user into surrendering sensitive information. (CVE-2008-0591, CVE-2008-0593) A flaw was found in the way Thunderbird handles certain chrome URLs. If a user has certain extensions installed, it could allow a malicious HTML mail message to steal sensitive session data. Note: this flaw does not affect a default installation of Thunderbird. (CVE-2008-0418) Note: JavaScript support is disabled by default in Thunderbird; the above issues are not exploitable unless JavaScript is enabled. A flaw was found in the way Thunderbird saves certain text files. If a remote site offers a file of type "plain/text", rather than "text/plain", Thunderbird will not show future "text/plain" content to the user, forcing them to save those files locally to view the content.(CVE-2008-0592) Users of thunderbird are advised to upgrade to these updated packages, which contain backported patches to resolve these issues. --------------------------------------------------------------------------------ChangeLog: * Tue Feb 26 2008 Christopher Aillon 2.0.0.12-1 - Update to 2.0.0.12 * Thu Nov 15 2007 Christopher Aillon 2.0.0.9-1 - Update to 2.0.0.9 * Wed Jul 25 2007 Martin Stransky 2.0.0.5-2 - added ligature pango fix * Fri Jul 20 2007 Kai Engert - 2.0.0.5-1 - 2.0.0.5 * Fri Jun 15 2007 Christopher Aillon 2.0.0.4-1 - 2.0.0.4 * Fri Jun 8 2007 Christopher Aillon 2.0.0.4-0.rc1 - 2.0.0.4 rc1 --------------------------------------------------------------------------------References: [ 1 ] Bug #431732 - CVE-2008-0412 Mozilla layout engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=431732 [ 2 ] Bug #431733 - CVE-2008-0413 Mozilla javascript engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=431733 [ 3 ] Bug #431739 - CVE-2008-0415 Mozilla arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=431739 [ 4 ] Bug #431748 - CVE-2008-0418 Mozilla chrome: directory traversal https://bugzilla.redhat.com/show_bug.cgi?id=431748 [ 5 ] Bug #431749 - CVE-2008-0419 Mozilla arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=431749 [ 6 ] Bug #431751 - CVE-2008-0591 Mozilla information disclosure flaw https://bugzilla.redhat.com/show_bug.cgi?id=431751 [ 7 ] Bug #431752 - CVE-2008-0592 Mozilla text file mishandling https://bugzilla.redhat.com/show_bug.cgi?id=431752 [ 8 ] Bug #431756 - CVE-2008-0593 Mozilla URL token stealing flaw https://bugzilla.redhat.com/show_bug.cgi?id=431756 [ 9 ] Bug #431750 - CVE-2008-0420 Mozilla information disclosure flaw https://bugzilla.redhat.com/show_bug.cgi?id=431750 [ 10 ] Bug #435123 - CVE-2008-0304 thunderbird/seamonkey: MIME External-Body Heap Overflow Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=435123 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update thunderbird' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Correct the address handling bugs in Thunderbird for Fedora 7, ensuring stability and safeguarding sensitive information from potential leaks.. Thunderbird HTML Update, Email Client Flaws, Fedora Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 28, 2008 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here