Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200606-21 ] Mozilla Thunderbird: Multiple vulnerabilities
Date: Mon, 19 Jun 2006 16:36:17
Message-Id: 200606191816.53783.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200606-21
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Mozilla Thunderbird: Multiple vulnerabilities
9 Date: June 19, 2006
10 Bugs: #135256
11 ID: 200606-21
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Several vulnerabilities in Mozilla Thunderbird allow cross site
19 scripting, JavaScript privilege escalation and possibly execution of
20 arbitrary code.
21
22 Background
23 ==========
24
25 Mozilla Thunderbird is the next-generation mail client from the Mozilla
26 project.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 mozilla-thunderbird < 1.5.0.4 >= 1.5.0.4
35 2 mozilla-thunderbird-bin < 1.5.0.4 >= 1.5.0.4
36 -------------------------------------------------------------------
37 2 affected packages on all of their supported architectures.
38 -------------------------------------------------------------------
39
40 Description
41 ===========
42
43 Several vulnerabilities were found and fixed in Mozilla Thunderbird.
44 For details, please consult the references below.
45
46 Impact
47 ======
48
49 A remote attacker could craft malicious emails that would leverage
50 these issues to inject and execute arbitrary script code with elevated
51 privileges, spoof content, and possibly execute arbitrary code with the
52 rights of the user running the application.
53
54 Workaround
55 ==========
56
57 There are no known workarounds for all the issues at this time.
58
59 Resolution
60 ==========
61
62 All Mozilla Thunderbird users should upgrade to the latest version:
63
64 # emerge --sync
65 # emerge --ask --oneshot --verbose ">=mail-client/mozilla-thunderbird-1.5.0.4"
66
67 All Mozilla Thunderbird binary users should upgrade to the latest
68 version:
69
70 # emerge --sync
71 # emerge --ask --oneshot --verbose ">=mail-client/mozilla-thunderbird-bin-1.5.0.4"
72
73 Note: There is no stable fixed version for the Alpha architecture yet.
74 Users of Mozilla Thunderbird on Alpha should consider unmerging it
75 until such a version is available.
76
77 References
78 ==========
79
80 [ 1 ] CVE-2006-2775
81 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2775
82 [ 2 ] CVE-2006-2776
83 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2776
84 [ 3 ] CVE-2006-2778
85 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2778
86 [ 4 ] CVE-2006-2779
87 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2779
88 [ 5 ] CVE-2006-2780
89 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2780
90 [ 6 ] CVE-2006-2781
91 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2781
92 [ 7 ] CVE-2006-2783
93 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2783
94 [ 8 ] CVE-2006-2786
95 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2786
96 [ 9 ] CVE-2006-2787
97 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2787
98 [ 10 ] Mozilla Foundation Security Advisories
99 http://www.mozilla.org/projects/security/known-vulnerabilities.html#Thunderbird
100
101 Availability
102 ============
103
104 This GLSA and any updates to it are available for viewing at
105 the Gentoo Security Website:
106
107 http://security.gentoo.org/glsa/glsa-200606-21.xml
108
109 Concerns?
110 =========
111
112 Security is a primary focus of Gentoo Linux and ensuring the
113 confidentiality and security of our users machines is of utmost
114 importance to us. Any security concerns should be addressed to
115 security@g.o or alternatively, you may file a bug at
116 http://bugs.gentoo.org.
117
118 License
119 =======
120
121 Copyright 2006 Gentoo Foundation, Inc; referenced text
122 belongs to its owner(s).
123
124 The contents of this document are licensed under the
125 Creative Commons - Attribution / Share Alike license.
126
127 http://creativecommons.org/licenses/by-sa/2.5