[GLSA-200711-24] Mozilla Thunderbird: Multiple vulnerabilities

Severity Normal
Affected Packages 2
Unaffected Packages 2
CVEs 2

Multiple vulnerabilities have been reported in Mozilla Thunderbird, which may allow user-assisted arbitrary remote code execution.

Background

Mozilla Thunderbird is a popular open-source email client from the
Mozilla project.

Description

Multiple vulnerabilities have been reported in Mozilla Thunderbird's
HTML browser engine (CVE-2007-5339) and JavaScript engine
(CVE-2007-5340) that can be exploited to cause a memory corruption.

Impact

A remote attacker could entice a user to read a specially crafted email
that could trigger one of the vulnerabilities, possibly leading to the
execution of arbitrary code.

Workaround

There is no known workaround at this time for all of these issues, but
some of them can be avoided by disabling JavaScript.

Resolution

All Mozilla Thunderbird users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-client/mozilla-thunderbird-2.0.0.9"

All Mozilla Thunderbird binary users should upgrade to the latest
version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-client/mozilla-thunderbird-bin-2.0.0.9"

ID
GLSA-200711-24
Severity
normal
URL
https://security.gentoo.org/glsa/200711-24
Published
2007-11-18T00:00:00
(17 years ago)
Modified
2007-11-18T00:00:00
(17 years ago)
Rights
Gentoo Foundation, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/mail-client/mozilla-thunderbird?distro=gentoo mail-client mozilla-thunderbird < 2.0.0.9 gentoo
Unaffected pkg:ebuild/mail-client/mozilla-thunderbird?distro=gentoo mail-client mozilla-thunderbird >= 2.0.0.9 gentoo
Affected pkg:ebuild/mail-client/mozilla-thunderbird-bin?distro=gentoo mail-client mozilla-thunderbird-bin < 2.0.0.9 gentoo
Unaffected pkg:ebuild/mail-client/mozilla-thunderbird-bin?distro=gentoo mail-client mozilla-thunderbird-bin >= 2.0.0.9 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...