Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu 10.04 LTS USN-958-1 High: Thunderbird Remote Code Execution

Several flaws were discovered in the browser engine of Thunderbird. If a user were tricked into viewing malicious content, a remote attacker could use this to crash Thunderbird or possibly run arbitrary code as the user invoking the program. (CVE-2010-1211, CVE-2010-1212) [More...]. ==========================================================Ubuntu Security Notice USN-958-1 July 26, 2010 thunderbird vulnerabilities CVE-2010-0654, CVE-2010-1205, CVE-2010-1211, CVE-2010-1212, CVE-2010-1213, CVE-2010-2752, CVE-2010-2753, CVE-2010-2754 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 10.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 10.04 LTS: thunderbird 3.0.6+build2+nobinonly-0ubuntu0.10.04.1 After a standard system update you need to restart Thunderbird to make all the necessary changes. Details follow: Several flaws were discovered in the browser engine of Thunderbird. If a user were tricked into viewing malicious content, a remote attacker could use this to crash Thunderbird or possibly run arbitrary code as the user invoking the program. (CVE-2010-1211, CVE-2010-1212) An integer overflow was discovered in how Thunderbird processed CSS values. An attacker could exploit this to crash Thunderbird or possibly run arbitrary code as the user invoking the program. (CVE-2010-2752) An integer overflow was discovered in how Thunderbird interpreted the XUL element. If a user were tricked into viewing malicious content, a remote attacker could use this to crash Thunderbird or possibly run arbitrary code as the user invoking the program. (CVE-2010-2753) Aki Helin discovered that libpng did not properly handle certain malformed PNG images. If a user were tricked into opening a crafted PNG file, an attacker could cause adenial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2010-1205) Yosuke Hasegawa discovered that the same-origin check in Thunderbird could be bypassed by utilizing the importScripts Web Worker method. If a user were tricked into viewing malicious content, an attacker could exploit this to read data from other domains. (CVE-2010-1213) Chris Evans discovered that Thunderbird did not properly process improper CSS selectors. If a user were tricked into viewing malicious content, an attacker could exploit this to read data from other domains. (CVE-2010-0654) Soroush Dalili discovered that Thunderbird did not properly handle script error output. An attacker could use this to access URL parameters from other domains. (CVE-2010-2754) Updated packages for Ubuntu 10.04: Source archives: Size/MD5: 92850 bc785c0348418206d4c8588ebaac0132 Size/MD5: 2412 a28a4d277235e3b6331a53471c467213 Size/MD5: 61048660 055766c535ba92126b033128d6540dd4 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 64137096 67d94866d04e19b71ad34521e78377cd Size/MD5: 5245646 e2eb4667407a5db752c62ad5a9f9df91 Size/MD5: 148998 4eb30277c88a46b9f65bf80d9ca984bd Size/MD5: 9296 4ed1c5b7788eb65fbccb960617217f44 Size/MD5: 11386116 cabfab2567a14b23bc0a46351ff4dbb7 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 64479186 0e6a1a89d7591d3d143cf12c12680ac6 Size/MD5: 5311316 870ff89004da182aac32cac5d38027e4 Size/MD5: 148154 6541fcf1d83a42fb02926a81f0a50858 Size/MD5: 9292 000175067546013dc9ed8b2dcc12072e Size/MD5: 10413876 9881b8ec4cd24233f1d7904997f04188 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 67105712 cfac784d5b5369f85ee450bb6b8aa06d Size/MD5: 5238112 1666f03c78dffbbfdfe27697b6c1a983 Size/MD5: 1533302b28241ad770ced2dc0deb4d04e91f62 Size/MD5: 9296 9caeeb0a6fd9694c0a2c26cfd7c007d9 Size/MD5: 11266520 cc5caab3d5bb3dedbfd08f0cdbbe1cc3 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 63651728 ecce696ddbd92be7a0e3d285317b3ab2 Size/MD5: 5219274 f791be2a355ccb057e3526d56b3952d7 Size/MD5: 144264 7ad54644130634dd28eec04fe01a2322 Size/MD5: 9298 e69ad6c66d4a5907d7fb61aa1a12a0f3 Size/MD5: 10521756 8247952d2eff647da997dd86595e869f . Identify severe flaws in Firefox as of August 30, 2011, impacting Ubuntu 12.04 LTS with significant online risks.. Thunderbird Update, Ubuntu Security Notice, Remote Code Execution, Integer Overflow, Denial of Service. . LinuxSecurity.com Team

Calendar 2 Jul 26, 2010 Ubuntu
98

Red Hat: RHSA-2008:0224-01 Moderate: Thunderbird Security Issue

Updated thunderbird packages that fix a security issue are now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: thunderbird security update Advisory ID: RHSA-2008:0224-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2008:0224.html Issue date: 2008-04-30 CVE Names: CVE-2008-1380 ==================================================================== 1. Summary: Updated thunderbird packages that fix a security issue are now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 RHEL Optional Productivity Applications (v. 5 server) - i386, x86_64 3. Description: Mozilla Thunderbird is a standalone mail and newsgroup client. A flaw was found in the processing of malformed JavaScript content. An HTML mail message containing such malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code as the user running Thunderbird. (CVE-2008-1380) Note: JavaScript support is disabled by default in Thunderbird; the above issue is not exploitable unless JavaScript is enabled. All Thunderbird users should upgrade to these updated packages, which contain backported patches to resolve these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevantto your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 440518 - CVE-2008-1380 Firefox JavaScript garbage collection crash 6. Package List: Red Hat Enterprise Linux AS version 4: Source: i386: thunderbird-1.5.0.12-11.el4.i386.rpm thunderbird-debuginfo-1.5.0.12-11.el4.i386.rpm ia64: thunderbird-1.5.0.12-11.el4.ia64.rpm thunderbird-debuginfo-1.5.0.12-11.el4.ia64.rpm ppc: thunderbird-1.5.0.12-11.el4.ppc.rpm thunderbird-debuginfo-1.5.0.12-11.el4.ppc.rpm s390: thunderbird-1.5.0.12-11.el4.s390.rpm thunderbird-debuginfo-1.5.0.12-11.el4.s390.rpm s390x: thunderbird-1.5.0.12-11.el4.s390x.rpm thunderbird-debuginfo-1.5.0.12-11.el4.s390x.rpm x86_64: thunderbird-1.5.0.12-11.el4.x86_64.rpm thunderbird-debuginfo-1.5.0.12-11.el4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: thunderbird-1.5.0.12-11.el4.i386.rpm thunderbird-debuginfo-1.5.0.12-11.el4.i386.rpm x86_64: thunderbird-1.5.0.12-11.el4.x86_64.rpm thunderbird-debuginfo-1.5.0.12-11.el4.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: thunderbird-1.5.0.12-11.el4.i386.rpm thunderbird-debuginfo-1.5.0.12-11.el4.i386.rpm ia64: thunderbird-1.5.0.12-11.el4.ia64.rpm thunderbird-debuginfo-1.5.0.12-11.el4.ia64.rpm x86_64: thunderbird-1.5.0.12-11.el4.x86_64.rpm thunderbird-debuginfo-1.5.0.12-11.el4.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: thunderbird-1.5.0.12-11.el4.i386.rpm thunderbird-debuginfo-1.5.0.12-11.el4.i386.rpm ia64: thunderbird-1.5.0.12-11.el4.ia64.rpm thunderbird-debuginfo-1.5.0.12-11.el4.ia64.rpm x86_64: thunderbird-1.5.0.12-11.el4.x86_64.rpm thunderbird-debuginfo-1.5.0.12-11.el4.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5client): Source: i386: thunderbird-1.5.0.12-12.el5_1.i386.rpm thunderbird-debuginfo-1.5.0.12-12.el5_1.i386.rpm x86_64: thunderbird-1.5.0.12-12.el5_1.x86_64.rpm thunderbird-debuginfo-1.5.0.12-12.el5_1.x86_64.rpm RHEL Optional Productivity Applications (v. 5 server): Source: i386: thunderbird-1.5.0.12-12.el5_1.i386.rpm thunderbird-debuginfo-1.5.0.12-12.el5_1.i386.rpm x86_64: thunderbird-1.5.0.12-12.el5_1.x86_64.rpm thunderbird-debuginfo-1.5.0.12-12.el5_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2008-1380 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2008 Red Hat, Inc. . Firefox security patch released targeting significant vulnerabilities in CentOS environments. Update now to boost defense.. thunderbird Security, Red Hat Updates, Security Patches, Enterprise Linux. . LinuxSecurity.com Team

Calendar 2 Apr 30, 2008 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here