Oval Definition:oval:org.mitre.oval:def:7681
Revision Date:2014-06-23Version:18
Title:DSA-1574 icedove -- several vulnerabilities
Description:Several remote vulnerabilities have been discovered in the Icedove mail client, an unbranded version of the Thunderbird client. The Common Vulnerabilities and Exposures project identifies the following problems: moz_bug_r_a4 discovered that variants of CVE-2007-3738 and CVE-2007-5338 allow the execution of arbitrary code through XPCNativeWrapper. moz_bug_r_a4 discovered that insecure handling of event handlers could lead to cross-site scripting. Boris Zbarsky, Johnny Stenback and moz_bug_r_a4 discovered that incorrect principal handling could lead to cross-site scripting and the execution of arbitrary code. Tom Ferris, Seth Spitzer, Martin Wargers, John Daggett and Mats Palmgren discovered crashes in the layout engine, which might allow the execution of arbitrary code. georgi, tgirmann and Igor Bukanov discovered crashes in the Javascript engine, which might allow the execution of arbitrary code.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2007-3738
CVE-2007-5338
CVE-2008-1233
CVE-2008-1234
CVE-2008-1235
CVE-2008-1236
CVE-2008-1237
DSA-1574
Platform(s):Debian GNU/Linux 4.0
Product(s):icedove
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • thunderbird-gnome-support is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR thunderbird-dev is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR mozilla-thunderbird is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR thunderbird is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR mozilla-thunderbird-dev is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR mozilla-thunderbird-typeaheadfind is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR thunderbird-dbg is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR thunderbird-typeaheadfind is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR mozilla-thunderbird-inspector is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR thunderbird-inspector is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND Packages section
  • icedove-typeaheadfind is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR icedove is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR icedove-inspector is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR icedove-dev is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR icedove-dbg is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • OR icedove-gnome-support is earlier than 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1
  • BACK