Oval Definition:oval:com.redhat.rhsa:def:20080908
Revision Date:2008-10-01Version:637
Title:RHSA-2008:0908: thunderbird security update (Moderate)
Description:Mozilla Thunderbird is a standalone mail and newsgroup client.

  • Several flaws were found in the processing of malformed HTML mail content. An HTML mail message containing malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code as the user running Thunderbird. (CVE-2008-0016, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062)

  • Several flaws were found in the way malformed HTML mail content was displayed. An HTML mail message containing specially crafted content could potentially trick a Thunderbird user into surrendering sensitive information. (CVE-2008-3835, CVE-2008-4067, CVE-2008-4068)

  • A flaw was found in Thunderbird that caused certain characters to be stripped from JavaScript code. This flaw could allow malicious JavaScript to bypass or evade script filters. (CVE-2008-4065, CVE-2008-4066)

    Note: JavaScript support is disabled by default in Thunderbird; the above issue is not exploitable unless JavaScript is enabled.

  • A heap based buffer overflow flaw was found in the handling of cancelled newsgroup messages. If the user cancels a specially crafted newsgroup message it could cause Thunderbird to crash or, potentially, execute arbitrary code as the user running Thunderbird. (CVE-2008-4070)

    All Thunderbird users should upgrade to these updated packages, which resolve these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-0016
    CVE-2008-3835
    CVE-2008-4058
    CVE-2008-4059
    CVE-2008-4060
    CVE-2008-4061
    CVE-2008-4062
    CVE-2008-4065
    CVE-2008-4066
    CVE-2008-4067
    CVE-2008-4068
    CVE-2008-4070
    RHSA-2008:0908
    RHSA-2008:0908-01
    RHSA-2008:0908-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND thunderbird is earlier than 0:1.5.0.12-16.el4
  • AND thunderbird is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND thunderbird is earlier than 0:2.0.0.17-1.el5
  • AND thunderbird is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 4 is installed
  • AND thunderbird is earlier than 0:1.5.0.12-16.el4
  • AND thunderbird is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND thunderbird is earlier than 0:2.0.0.17-1.el5
  • AND thunderbird is signed with Red Hat redhatrelease key
  • BACK