[FEDORA-2008-3557] Fedora 8: thunderbird

Severity High
Affected Packages 1
CVEs 6

Mozilla Thunderbird is a standalone mail and newsgroup client. Several flaws
were found in the processing of some malformed HTML mail content. An HTML mail
message containing such malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code as the user running Thunderbird.
(CVE-2008-1233, CVE-2008-1235, CVE-2008-1236, CVE-2008-1237) Several flaws
were found in the display of malformed web content. An HTML mail message
containing specially-crafted content could, potentially, trick a user into
surrendering sensitive information. (CVE-2008-1234) A flaw was found in the
processing of malformed JavaScript content. An HTML mail message containing
such malicious content could cause Thunderbird to crash or, potentially,
execute arbitrary code as the user running Thunderbird. (CVE-2008-1380)
Note: JavaScript support is disabled by default in Thunderbird; the above issue
is not exploitable unless JavaScript is enabled. All Thunderbird users should
upgrade to these updated packages, which contain backported patches to resolve
these issues.

Package Affected Version
pkg:rpm/fedora/thunderbird?distro=fedora-8 <
Source # ID Name URL
Bugzilla 440518 Bug #440518 - CVE-2008-1380 Firefox JavaScript garbage collection crash https://bugzilla.redhat.com/show_bug.cgi?id=440518
Bugzilla 438721 Bug #438721 - CVE-2008-1237 javascript crashes https://bugzilla.redhat.com/show_bug.cgi?id=438721
Bugzilla 438717 Bug #438717 - CVE-2008-1235 chrome privilege via wrong principal https://bugzilla.redhat.com/show_bug.cgi?id=438717
Bugzilla 438713 Bug #438713 - CVE-2008-1233 Mozilla products XPCNativeWrapper pollution https://bugzilla.redhat.com/show_bug.cgi?id=438713
Bugzilla 438715 Bug #438715 - CVE-2008-1234 universal XSS using event handlers https://bugzilla.redhat.com/show_bug.cgi?id=438715
Bugzilla 438718 Bug #438718 - CVE-2008-1236 browser engine crashes https://bugzilla.redhat.com/show_bug.cgi?id=438718
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/thunderbird?distro=fedora-8 fedora thunderbird < fedora-8
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date