Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 200606-21 ] Mozilla Thunderbird: Multiple vulnerabilities
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Advocate
Advocate


Joined: 12 May 2004
Posts: 2663

PostPosted: Mon Jun 19, 2006 6:26 pm    Post subject: [ GLSA 200606-21 ] Mozilla Thunderbird: Multiple vulnerabili Reply with quote

Gentoo Linux Security Advisory

Title: Mozilla Thunderbird: Multiple vulnerabilities (GLSA 200606-21)
Severity: normal
Exploitable: remote
Date: June 19, 2006
Bug(s): #135256
ID: 200606-21

Synopsis

Several vulnerabilities in Mozilla Thunderbird allow cross site scripting, JavaScript privilege escalation and possibly execution of arbitrary code.

Background

Mozilla Thunderbird is the next-generation mail client from the Mozilla project.

Affected Packages

Package: mail-client/mozilla-thunderbird
Vulnerable: < 1.5.0.4
Unaffected: >= 1.5.0.4
Architectures: All supported architectures

Package: mail-client/mozilla-thunderbird-bin
Vulnerable: < 1.5.0.4
Unaffected: >= 1.5.0.4
Architectures: All supported architectures


Description

Several vulnerabilities were found and fixed in Mozilla Thunderbird. For details, please consult the references below.

Impact

A remote attacker could craft malicious emails that would leverage these issues to inject and execute arbitrary script code with elevated privileges, spoof content, and possibly execute arbitrary code with the rights of the user running the application.

Workaround

There are no known workarounds for all the issues at this time.

Resolution

All Mozilla Thunderbird users should upgrade to the latest version:
Code:
# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-client/mozilla-thunderbird-1.5.0.4"
All Mozilla Thunderbird binary users should upgrade to the latest version:
Code:
# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-client/mozilla-thunderbird-bin-1.5.0.4"
Note: There is no stable fixed version for the Alpha architecture yet. Users of Mozilla Thunderbird on Alpha should consider unmerging it until such a version is available.

References

CVE-2006-2775
CVE-2006-2776
CVE-2006-2778
CVE-2006-2779
CVE-2006-2780
CVE-2006-2781
CVE-2006-2783
CVE-2006-2786
CVE-2006-2787
Mozilla Foundation Security Advisories


Last edited by GLSA on Sun Jul 30, 2006 4:18 am; edited 2 times in total
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum