Oval Definition:oval:com.redhat.rhsa:def:20110887
Revision Date:2011-06-21Version:635
Title:RHSA-2011:0887: thunderbird security update (Critical)
Description:Mozilla Thunderbird is a standalone mail and newsgroup client.

  • A flaw was found in the way Thunderbird handled malformed JPEG images. An HTML mail message containing a malicious JPEG image could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2011-2377)

  • Multiple dangling pointer flaws were found in Thunderbird. Malicious HTML content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2011-0083, CVE-2011-0085, CVE-2011-2363)

  • Several flaws were found in the processing of malformed HTML content. Malicious HTML content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2011-2364, CVE-2011-2365, CVE-2011-2374, CVE-2011-2375, CVE-2011-2376)

  • An integer overflow flaw was found in the way Thunderbird handled JavaScript Array objects. Malicious content could cause Thunderbird to execute JavaScript with the privileges of the user running Thunderbird. (CVE-2011-2371)

  • A use-after-free flaw was found in the way Thunderbird handled malformed JavaScript. Malicious content could cause Thunderbird to execute JavaScript with the privileges of the user running Thunderbird. (CVE-2011-2373)

  • It was found that Thunderbird could treat two separate cookies (for web content) as interchangeable if both were for the same domain name but one of those domain names had a trailing "." character. This violates the same-origin policy and could possibly lead to data being leaked to the wrong domain. (CVE-2011-2362)

    All Thunderbird users should upgrade to this updated package, which resolves these issues. All running instances of Thunderbird must be restarted for the update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-0083
    CVE-2011-0085
    CVE-2011-2362
    CVE-2011-2363
    CVE-2011-2364
    CVE-2011-2365
    CVE-2011-2371
    CVE-2011-2373
    CVE-2011-2374
    CVE-2011-2375
    CVE-2011-2376
    CVE-2011-2377
    CVE-2011-2605
    RHSA-2011:0887
    RHSA-2011:0887-01
    RHSA-2011:0887-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND thunderbird is earlier than 0:1.5.0.12-39.el4
  • AND thunderbird is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND thunderbird is earlier than 0:2.0.0.24-18.el5_6
  • AND thunderbird is signed with Red Hat redhatrelease2 key
  • BACK