[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2011:080 -- Mandriva mozilla-thunderbird

ID: oval:org.secpod.oval:def:301006Date: (C)2012-01-07   (M)2023-11-18
Class: PATCHFamily: unix




Security issues were identified and fixed in mozilla-thunderbird: Security researcher Soroush Dalili reported that the resource: protocol could be exploited to allow directory traversal on Windows and the potential loading of resources from non-permitted locations. The impact would depend on whether interesting files existed in predictable locations in a useful format. For example, the existence or non-existence of particular images might indicate whether certain software was installed . Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code . The mozilla-thunderbird-lightning package shipped with MDVSA-2011:042 had a packaging bug that prevented extension to be loaded . Packages for 2009.0 are provided as of the Extended Maintenance Program

Platform:
Mandriva Linux 2010.0
Mandriva Linux 2010.1
Mandriva Linux 2009.0
Product:
mozilla-thunderbird
Reference:
MDVSA-2011:080
CVE-2011-0072
CVE-2011-0078
CVE-2011-0077
CVE-2011-0075
CVE-2011-0074
CVE-2011-0080
CVE-2011-0070
CVE-2011-0069
CVE-2011-0081
CVE-2011-0071
CVE    10
CVE-2011-0075
CVE-2011-0074
CVE-2011-0069
CVE-2011-0077
...
CPE    3
cpe:/o:mandriva:linux:2009.0
cpe:/o:mandriva:linux:2010.1
cpe:/o:mandriva:linux:2010.0

© SecPod Technologies