[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

USN-958-1 -- thunderbird vulnerabilities

ID: oval:org.secpod.oval:def:700128Date: (C)2011-01-28   (M)2024-02-19
Class: PATCHFamily: unix




Several flaws were discovered in the browser engine of Thunderbird. If a user were tricked into viewing malicious content, a remote attacker could use this to crash Thunderbird or possibly run arbitrary code as the user invoking the program. An integer overflow was discovered in how Thunderbird processed CSS values. An attacker could exploit this to crash Thunderbird or possibly run arbitrary code as the user invoking the program. An integer overflow was discovered in how Thunderbird interpreted the XUL element. If a user were tricked into viewing malicious content, a remote attacker could use this to crash Thunderbird or possibly run arbitrary code as the user invoking the program. Aki Helin discovered that libpng did not properly handle certain malformed PNG images. If a user were tricked into opening a crafted PNG file, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. Yosuke Hasegawa discovered that the same-origin check in Thunderbird could be bypassed by utilizing the importScripts Web Worker method. If a user were tricked into viewing malicious content, an attacker could exploit this to read data from other domains. Chris Evans discovered that Thunderbird did not properly process improper CSS selectors. If a user were tricked into viewing malicious content, an attacker could exploit this to read data from other domains. Soroush Dalili discovered that Thunderbird did not properly handle script error output. An attacker could use this to access URL parameters from other domains

Platform:
Ubuntu 10.04
Product:
thunderbird
Reference:
USN-958-1
CVE-2010-0654
CVE-2010-1205
CVE-2010-1211
CVE-2010-1212
CVE-2010-1213
CVE-2010-2752
CVE-2010-2753
CVE-2010-2754
CVE    8
CVE-2010-1211
CVE-2010-2752
CVE-2010-1212
CVE-2010-0654
...
CPE    1
cpe:/o:ubuntu:ubuntu_linux:10.04

© SecPod Technologies