Oval Definition:oval:org.mitre.oval:def:6699
Revision Date:2014-06-23Version:19
Title:DSA-2025 icedove -- several vulnerabilities
Description:Several remote vulnerabilities have been discovered in the Icedove mail client, an unbranded version of the Thunderbird mail client. The Common Vulnerabilities and Exposures project identifies the following problems: Dan Kaminsky and Moxie Marlinspike discovered that icedove does not properly handle a "\0" character in a domain name in the subject's Common Name field of an X.509 certificate. Moxie Marlinspike reported a heap overflow vulnerability in the code that handles regular expressions in certificate names. monarch2020 discovered an integer overflow in a base64 decoding function. Josh Soref discovered a crash in the BinHex decoder. Carsten Book reported a crash in the JavaScript engine. Ludovic Hirlimann reported a crash indexing some messages with attachments, which could lead to the execution of arbitrary code.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-2404
CVE-2009-2408
CVE-2009-2463
CVE-2009-3072
CVE-2009-3075
CVE-2010-0163
DSA-2025
Platform(s):Debian GNU/Linux 5.0
Product(s):icedove
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is hppa
  • AND Packages section
  • icedove-dev is earlier than 2.0.0.24-0lenny1
  • OR icedove-dbg is earlier than 2.0.0.24-0lenny1
  • OR icedove-gnome-support is earlier than 2.0.0.24-0lenny1
  • OR icedove is earlier than 2.0.0.24-0lenny1
  • BACK