Oval Definition:oval:org.mitre.oval:def:13110
Revision Date:2014-07-07Version:20
Title:USN-958-1 -- thunderbird vulnerabilities
Description:Several flaws were discovered in the browser engine of Thunderbird. If a user were tricked into viewing malicious content, a remote attacker could use this to crash Thunderbird or possibly run arbitrary code as the user invoking the program. An integer overflow was discovered in how Thunderbird processed CSS values. An attacker could exploit this to crash Thunderbird or possibly run arbitrary code as the user invoking the program. An integer overflow was discovered in how Thunderbird interpreted the XUL element. If a user were tricked into viewing malicious content, a remote attacker could use this to crash Thunderbird or possibly run arbitrary code as the user invoking the program. Aki Helin discovered that libpng did not properly handle certain malformed PNG images. If a user were tricked into opening a crafted PNG file, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. Yosuke Hasegawa discovered that the same-origin check in Thunderbird could be bypassed by utilizing the importScripts Web Worker method. If a user were tricked into viewing malicious content, an attacker could exploit this to read data from other domains. Chris Evans discovered that Thunderbird did not properly process improper CSS selectors. If a user were tricked into viewing malicious content, an attacker could exploit this to read data from other domains. Soroush Dalili discovered that Thunderbird did not properly handle script error output. An attacker could use this to access URL parameters from other domains
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2010-0654
CVE-2010-1205
CVE-2010-1211
CVE-2010-1212
CVE-2010-1213
CVE-2010-2752
CVE-2010-2753
CVE-2010-2754
USN-958-1
USN-958-1
Platform(s):Ubuntu 10.04
Product(s):thunderbird
Definition Synopsis
  • Ubuntu 10.04 is installed
  • AND Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is powerpc
  • AND Packages section
  • thunderbird-gnome-support-dbg DPKG is earlier than 3.0.6+build2+nobinonly-0ubuntu0.10.04.1
  • OR thunderbird-dbg DPKG is earlier than 3.0.6+build2+nobinonly-0ubuntu0.10.04.1
  • OR thunderbird DPKG is earlier than 3.0.6+build2+nobinonly-0ubuntu0.10.04.1
  • OR thunderbird-dev DPKG is earlier than 3.0.6+build2+nobinonly-0ubuntu0.10.04.1
  • OR thunderbird-gnome-support DPKG is earlier than 3.0.6+build2+nobinonly-0ubuntu0.10.04.1
  • BACK