Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update for thunderbird is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Critical: thunderbird security update Advisory ID: RHSA-2022:4772-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:4772 Issue date: 2022-05-27 CVE Names: CVE-2022-1529 CVE-2022-1802 ==================================================================== 1. Summary: An update for thunderbird is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 91.9.1. Security Fix(es): * Mozilla: Untrusted input used in JavaScript object indexing, leading to prototype pollution (CVE-2022-1529) * Mozilla: Prototype pollution in Top-Level Await implementation (CVE-2022-1802) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of Thunderbird must be restartedfor the update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2089217 - CVE-2022-1802 Mozilla: Prototype pollution in Top-Level Await implementation 2089218 - CVE-2022-1529 Mozilla: Untrusted input used in JavaScript object indexing, leading to prototype pollution 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: thunderbird-91.9.1-1.el9_0.src.rpm aarch64: thunderbird-91.9.1-1.el9_0.aarch64.rpm thunderbird-debuginfo-91.9.1-1.el9_0.aarch64.rpm thunderbird-debugsource-91.9.1-1.el9_0.aarch64.rpm ppc64le: thunderbird-91.9.1-1.el9_0.ppc64le.rpm thunderbird-debuginfo-91.9.1-1.el9_0.ppc64le.rpm thunderbird-debugsource-91.9.1-1.el9_0.ppc64le.rpm s390x: thunderbird-91.9.1-1.el9_0.s390x.rpm thunderbird-debuginfo-91.9.1-1.el9_0.s390x.rpm thunderbird-debugsource-91.9.1-1.el9_0.s390x.rpm x86_64: thunderbird-91.9.1-1.el9_0.x86_64.rpm thunderbird-debuginfo-91.9.1-1.el9_0.x86_64.rpm thunderbird-debugsource-91.9.1-1.el9_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-1529 https://access.redhat.com/security/cve/CVE-2022-1802 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYpEx+tzjgjWX9erEAQj4Nw//UccWBnV34jWNz3LYC+EdQi32Xp5qNU4s aQJMfrJRGEpIRCjrgar0C6UIK+pJLKaSDi9EFneXd33YOi6VWsx/6p+1Y4GLV6lB glMkv/oVpkP7OM0UYIlIwJAsZiGQnUbfBOqDzUI0g/mRZB47kr17oDJzSbKAd3to vM0awAu17XT7D++lZfQ1NZX0vIMcnJapEbUgMkNbWXkRTWrFg+9qdUkhbxaelDRx 5jqJXIFgrsCQ/Usxf3FDQlu4nCU6rnUyJcko++/P2IHSM+g49/oKUD1Jw1wMlJdf 9Vgv5buDtw2R0lpYZRFcIX2uHpCvFjMGQKULDEWlP1E1kAve+Pjj83kdFCLnbFgw EOPc63KHQ6/I/51krPCnJwaC8EqsJTNvhigBgCRv7ZtlcsK5BO7vGRb3cbdnCIPq aPcCHQAvqtBx16HMHUyidPuFcvqwGTWrFn+BbQb00OXwF5jlbd9O6yGD3Ga/zhxk 9WrE6oUI/dw1EECVt5TpsJ44aczlKkhStqOD7JC0TIgTtLEnaUOMbYOfblttWCrw mz/sZYamazsr/zme2w8IvJs5TBcKF/A2bWYZKI6fji9zzYyQIVK/afH4JG45ULT3 pFR2W5nLm5cydtcSdSDR73iZDsUviRFQoi7dLBYpAp9PtHD8L7EgieiMFVr1UR6y BDmGMV/eZJM=2JqP -----END PGP SIGNATURE----- -- RHSA-announce mailing list
KDE PIM could be made to execute JavaScript if it opened a specially crafted email.. =========================================================================Ubuntu Security Notice USN-1512-1 July 19, 2012 kdepim vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS - Ubuntu 11.10 Summary: KDE PIM could be made to execute JavaScript if it opened a specially crafted email. Software Description: - kdepim: Personal Information Management apps Details: It was discovered that KDE PIM html renderer incorrectly enabled JavaScript, Java and Plugins. A remote attacker could use this flaw to send an email with embedded JavaScript that possibly executes when opened. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: kdepim 4:4.8.4a-0ubuntu0.3 Ubuntu 11.10: kdepim 4:4.7.4+git111222-0ubuntu0.3 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1512-1 CVE-2012-3413 Package Information: https://launchpad.net/ubuntu/+source/kdepim/4:4.8.4a-0ubuntu0.3 https://launchpad.net/ubuntu/+source/kdepim/4:4.7.4+git111222-0ubuntu0.3 . New KDE PIM flaw in Ubuntu enables JavaScript execution through specially designed emails. Security update advised for user protection.. KDEPIM, JavaScript Exploit, Email Security, Ubuntu Updates. . Severity: Important. LinuxSecurity.com Team
Updated thunderbird packages that fix several security bugs are now available for Red Hat Enterprise Linux 4 and 5. A malicious HTML email message containing JavaScript code could cause Thunderbird to crash or potentially execute arbitrary code as the user running Thunderbird. JavaScript support is disabled by default in Thunderbird; these issues are not exploitable unless the user has enabled JavaScript. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: thunderbird security update Advisory ID: RHSA-2007:0723-01 Advisory URL: https://access.redhat.com/errata/RHSA-2007:0723.html Issue date: 2007-07-18 Updated on: 2007-07-18 Product: Red Hat Enterprise Linux CVE Names: CVE-2007-3089 CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3738 - ---------------------------------------------------------------------1. Summary: Updated thunderbird packages that fix several security bugs are now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 RHEL Optional Productivity Applications (v. 5 server) - i386, x86_64 3. Problem description: Mozilla Thunderbird is a standalone mail and newsgroup client. Several flaws were found in the way Thunderbird processed certain malformed JavaScript code. A malicious HTML email message containing JavaScript code could causeThunderbird to crash or potentially execute arbitrary code as the user running Thunderbird. JavaScript support is disabled by default in Thunderbird; these issues are not exploitable unless the user has enabled JavaScript. (CVE-2007-3089, CVE-2007-3734, CVE-2007-3735, CVE-2007-3736, CVE-2007-3737, CVE-2007-3738) Users of Thunderbird are advised to upgrade to these erratum packages, which contain backported patches that correct these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bug IDs fixed (http://bugzilla.redhat.com/): 248518 - CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738) 6. RPMs required: Red Hat Enterprise Linux AS version 4: SRPMS: 538c43a537434bf87d1e426e9d1dd165 thunderbird-1.5.0.12-0.3.el4.src.rpm i386: 6f70b6a69cdb029118b546fd51471ba5 thunderbird-1.5.0.12-0.3.el4.i386.rpm 23e9d83d8ca383c4fa31375ea6739c21 thunderbird-debuginfo-1.5.0.12-0.3.el4.i386.rpm ia64: e16916261b3fdac23f8a3f44e9801a93 thunderbird-1.5.0.12-0.3.el4.ia64.rpm ba23bf28e73878031d709384d118ff3c thunderbird-debuginfo-1.5.0.12-0.3.el4.ia64.rpm ppc: 7ea6c491fe5e4231e2835a0f17f631e0 thunderbird-1.5.0.12-0.3.el4.ppc.rpm c9fa0388d9a7bf958cb234d9d1cddaa2 thunderbird-debuginfo-1.5.0.12-0.3.el4.ppc.rpm s390: a04a2f762f6639db33595db7730749a0 thunderbird-1.5.0.12-0.3.el4.s390.rpm 3161e0788560ba0a730d1a60004679f8 thunderbird-debuginfo-1.5.0.12-0.3.el4.s390.rpm s390x: db326caf35d4b24a5cd39dc671d7aaa2 thunderbird-1.5.0.12-0.3.el4.s390x.rpm d505b9b26392b922700106caedd20e96 thunderbird-debuginfo-1.5.0.12-0.3.el4.s390x.rpm x86_64: ed4e5c71027cc960b299865691099eb2 thunderbird-1.5.0.12-0.3.el4.x86_64.rpm 0200ab2c5a402a570c626b8de6aa532c thunderbird-debuginfo-1.5.0.12-0.3.el4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: 538c43a537434bf87d1e426e9d1dd165 thunderbird-1.5.0.12-0.3.el4.src.rpm i386: 6f70b6a69cdb029118b546fd51471ba5 thunderbird-1.5.0.12-0.3.el4.i386.rpm 23e9d83d8ca383c4fa31375ea6739c21 thunderbird-debuginfo-1.5.0.12-0.3.el4.i386.rpm x86_64: ed4e5c71027cc960b299865691099eb2 thunderbird-1.5.0.12-0.3.el4.x86_64.rpm 0200ab2c5a402a570c626b8de6aa532c thunderbird-debuginfo-1.5.0.12-0.3.el4.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: 538c43a537434bf87d1e426e9d1dd165 thunderbird-1.5.0.12-0.3.el4.src.rpm i386: 6f70b6a69cdb029118b546fd51471ba5 thunderbird-1.5.0.12-0.3.el4.i386.rpm 23e9d83d8ca383c4fa31375ea6739c21 thunderbird-debuginfo-1.5.0.12-0.3.el4.i386.rpm ia64: e16916261b3fdac23f8a3f44e9801a93 thunderbird-1.5.0.12-0.3.el4.ia64.rpm ba23bf28e73878031d709384d118ff3c thunderbird-debuginfo-1.5.0.12-0.3.el4.ia64.rpm x86_64: ed4e5c71027cc960b299865691099eb2 thunderbird-1.5.0.12-0.3.el4.x86_64.rpm 0200ab2c5a402a570c626b8de6aa532c thunderbird-debuginfo-1.5.0.12-0.3.el4.x86_64.rpm Red Hat Enterprise Linux WS version 4: SRPMS: 538c43a537434bf87d1e426e9d1dd165 thunderbird-1.5.0.12-0.3.el4.src.rpm i386: 6f70b6a69cdb029118b546fd51471ba5 thunderbird-1.5.0.12-0.3.el4.i386.rpm 23e9d83d8ca383c4fa31375ea6739c21 thunderbird-debuginfo-1.5.0.12-0.3.el4.i386.rpm ia64: e16916261b3fdac23f8a3f44e9801a93 thunderbird-1.5.0.12-0.3.el4.ia64.rpm ba23bf28e73878031d709384d118ff3c thunderbird-debuginfo-1.5.0.12-0.3.el4.ia64.rpm x86_64: ed4e5c71027cc960b299865691099eb2 thunderbird-1.5.0.12-0.3.el4.x86_64.rpm 0200ab2c5a402a570c626b8de6aa532c thunderbird-debuginfo-1.5.0.12-0.3.el4.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5 client): SRPMS: 4373c55c246ecebbf9bf1ba333678676 thunderbird-1.5.0.12-3.el5.src.rpm i386: fbb7947309c94885611478b94f31cd70 thunderbird-1.5.0.12-3.el5.i386.rpm 067a33e1d0fabbe722e2f8ded2b2057e thunderbird-debuginfo-1.5.0.12-3.el5.i386.rpm x86_64: 6654c7bed76f6d1470fd3e7d6ff81327 thunderbird-1.5.0.12-3.el5.x86_64.rpm 34840f0236cd5bbd9f42c03d30c42828 thunderbird-debuginfo-1.5.0.12-3.el5.x86_64.rpm RHEL Optional Productivity Applications (v. 5 server): SRPMS: 4373c55c246ecebbf9bf1ba333678676 thunderbird-1.5.0.12-3.el5.src.rpm i386: fbb7947309c94885611478b94f31cd70 thunderbird-1.5.0.12-3.el5.i386.rpm 067a33e1d0fabbe722e2f8ded2b2057e thunderbird-debuginfo-1.5.0.12-3.el5.i386.rpm x86_64: 6654c7bed76f6d1470fd3e7d6ff81327 thunderbird-1.5.0.12-3.el5.x86_64.rpm 34840f0236cd5bbd9f42c03d30c42828 thunderbird-debuginfo-1.5.0.12-3.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2007-3089 https://www.cve.org/CVERecord?id=CVE-2007-3734 https://www.cve.org/CVERecord?id=CVE-2007-3735 https://www.cve.org/CVERecord?id=CVE-2007-3736 https://www.cve.org/CVERecord?id=CVE-2007-3737 https://www.cve.org/CVERecord?id=CVE-2007-3738 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2007 Red Hat, Inc. . The latest advisory from Red Hat outlines a crucial update for Thunderbird, focusing on rectifying multiple vulnerabilities within the email application and implementing necessary patches.. Thunderbird Update, Red Hat Advisory, Email Client Issues. . LinuxSecurity.com Team
Several vulnerabilities in the Mozilla Suite allow attacks ranging from the execution of javascript code with elevated privileges to information leakage. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200507-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Mozilla Suite: Multiple vulnerabilities Date: July 26, 2005 Bugs: #98846 ID: 200507-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Several vulnerabilities in the Mozilla Suite allow attacks ranging from the execution of javascript code with elevated privileges to information leakage. Background ========= The Mozilla Suite is an all-in-one Internet application suite including a web browser, an advanced e-mail and newsgroup client, IRC client and HTML editor. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-client/mozilla < 1.7.10 > = 1.7.10 2 www-client/mozilla-bin < 1.7.10 > = 1.7.10 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== The following vulnerabilities were found and fixed in the Mozilla Suite: * "moz_bug_r_a4" and "shutdown" discovered that the Mozilla Suite was improperly cloning base objects (MFSA 2005-56). * "moz_bug_r_a4" reported that the suite failed to validate XHTML DOM nodes properly (MFSA 2005-55). * Secunia reported thatalerts and prompts scripts are presented with the generic title [JavaScript Application] which could lead to tricking a user (MFSA 2005-54). * Andreas Sandblad of Secunia reported that top.focus() can be called in the context of a child frame even if the framing page comes from a different origin and has overridden the focus() routine (MFSA 2005-52). * Secunia reported that a frame-injection spoofing bug which was fixed in earlier versions, was accidently bypassed in Mozilla Suite 1.7.7 (MFSA 2005-51). * "shutdown" reported that InstallVersion.compareTo() might be exploitable. When it gets an object rather than a string, the browser would generally crash with an access violation (MFSA 2005-50). * Matthew Mastracci reported that by forcing a page navigation immediately after calling the install method can end up running in the context of the new page selected by the attacker (MFSA 2005-48). * "moz_bug_r_a4" reported that XBL scripts run even when Javascript is disabled (MFSA 2005-46). * Omar Khan, Jochen, "shutdown" and Matthew Mastracci reported that the Mozilla Suite incorrectly distinguished between true events like mouse clicks or keystrokes and synthetic events generated by a web content (MFSA 2005-45). Impact ===== A remote attacker could craft malicious web pages that would leverage these issues to inject and execute arbitrary javascript code with elevated privileges, steal cookies or other information from web pages, or spoof content. Workaround ========= There is no known workaround at this time. Resolution ========= All Mozilla Suite users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-client/mozilla-1.7.10" All Mozilla Suite binary users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-client/mozilla-bin-1.7.10" References ========= [ 1 ] Mozilla Foundation Security Advisories https://www.mozilla.org/en-US/security/known-vulnerabilities/ Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200507-24 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Florian Wesch has discovered a problem (reported to bugtraq) with the way how Netscape handles comments in GIF files.. ---------------------------------------------------------------------------- Debian Security Advisory DSA 051-1
Get the latest Linux and open source security news straight to your inbox.