LWN.net Logo

Mageia alert MGASA-2013-0021 (thunderbird)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2013-0021: thunderbird-10.0.12-1.mga2 (2/core)
Date:  Sat, 26 Jan 2013 19:04:07 +0100
Message-ID:  <20130126180407.GA11867@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2013-0021 Date: January 26th, 2013 Affected releases: 2 Description: Updated thunderbird packages fix security vulnerabilities: Several flaws were found in the processing of malformed content. Malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird (CVE-2013-0744, CVE-2013-0746, CVE-2013-0750, CVE-2013-0753, CVE-2013-0754, CVE-2013-0762, CVE-2013-0766, CVE-2013-0767, CVE-2013-0769). A flaw was found in the way Chrome Object Wrappers were implemented. Malicious content could be used to cause Thunderbird to execute arbitrary code via plug-ins installed in Thunderbird (CVE-2013-0758). A flaw in the way Thunderbird displayed URL values could allow malicious content or a user to perform a phishing attack (CVE-2013-0759). An information disclosure flaw was found in the way certain JavaScript functions were implemented in Thunderbird. An attacker could use this flaw to bypass Address Space Layout Randomization (ASLR) and other security restrictions (CVE-2013-0748). Updated Packages: i586: nsinstall-10.0.12-1.mga2.i586.rpm thunderbird-10.0.12-1.mga2.i586.rpm thunderbird-enigmail-10.0.12-1.mga2.i586.rpm thunderbird-ar-10.0.12-1.mga2.noarch.rpm thunderbird-ast-10.0.12-1.mga2.noarch.rpm thunderbird-be-10.0.12-1.mga2.noarch.rpm thunderbird-bg-10.0.12-1.mga2.noarch.rpm thunderbird-bn_BD-10.0.12-1.mga2.noarch.rpm thunderbird-br-10.0.12-1.mga2.noarch.rpm thunderbird-ca-10.0.12-1.mga2.noarch.rpm thunderbird-cs-10.0.12-1.mga2.noarch.rpm thunderbird-da-10.0.12-1.mga2.noarch.rpm thunderbird-de-10.0.12-1.mga2.noarch.rpm thunderbird-el-10.0.12-1.mga2.noarch.rpm thunderbird-en_GB-10.0.12-1.mga2.noarch.rpm thunderbird-es_AR-10.0.12-1.mga2.noarch.rpm thunderbird-es_ES-10.0.12-1.mga2.noarch.rpm thunderbird-et-10.0.12-1.mga2.noarch.rpm thunderbird-eu-10.0.12-1.mga2.noarch.rpm thunderbird-fi-10.0.12-1.mga2.noarch.rpm thunderbird-fr-10.0.12-1.mga2.noarch.rpm thunderbird-fy-10.0.12-1.mga2.noarch.rpm thunderbird-ga-10.0.12-1.mga2.noarch.rpm thunderbird-gd-10.0.12-1.mga2.noarch.rpm thunderbird-gl-10.0.12-1.mga2.noarch.rpm thunderbird-he-10.0.12-1.mga2.noarch.rpm thunderbird-hu-10.0.12-1.mga2.noarch.rpm thunderbird-id-10.0.12-1.mga2.noarch.rpm thunderbird-is-10.0.12-1.mga2.noarch.rpm thunderbird-it-10.0.12-1.mga2.noarch.rpm thunderbird-ja-10.0.12-1.mga2.noarch.rpm thunderbird-ko-10.0.12-1.mga2.noarch.rpm thunderbird-lt-10.0.12-1.mga2.noarch.rpm thunderbird-nb_NO-10.0.12-1.mga2.noarch.rpm thunderbird-nl-10.0.12-1.mga2.noarch.rpm thunderbird-nn_NO-10.0.12-1.mga2.noarch.rpm thunderbird-pa_IN-10.0.12-1.mga2.noarch.rpm thunderbird-pl-10.0.12-1.mga2.noarch.rpm thunderbird-pt_BR-10.0.12-1.mga2.noarch.rpm thunderbird-pt_PT-10.0.12-1.mga2.noarch.rpm thunderbird-ro-10.0.12-1.mga2.noarch.rpm thunderbird-ru-10.0.12-1.mga2.noarch.rpm thunderbird-si-10.0.12-1.mga2.noarch.rpm thunderbird-sk-10.0.12-1.mga2.noarch.rpm thunderbird-sl-10.0.12-1.mga2.noarch.rpm thunderbird-sq-10.0.12-1.mga2.noarch.rpm thunderbird-sv_SE-10.0.12-1.mga2.noarch.rpm thunderbird-ta_LK-10.0.12-1.mga2.noarch.rpm thunderbird-tr-10.0.12-1.mga2.noarch.rpm thunderbird-uk-10.0.12-1.mga2.noarch.rpm thunderbird-vi-10.0.12-1.mga2.noarch.rpm thunderbird-zh_CN-10.0.12-1.mga2.noarch.rpm thunderbird-zh_TW-10.0.12-1.mga2.noarch.rpm x86_64: nsinstall-10.0.12-1.mga2.x86_64.rpm thunderbird-10.0.12-1.mga2.x86_64.rpm thunderbird-enigmail-10.0.12-1.mga2.x86_64.rpm thunderbird-ar-10.0.12-1.mga2.noarch.rpm thunderbird-ast-10.0.12-1.mga2.noarch.rpm thunderbird-be-10.0.12-1.mga2.noarch.rpm thunderbird-bg-10.0.12-1.mga2.noarch.rpm thunderbird-bn_BD-10.0.12-1.mga2.noarch.rpm thunderbird-br-10.0.12-1.mga2.noarch.rpm thunderbird-ca-10.0.12-1.mga2.noarch.rpm thunderbird-cs-10.0.12-1.mga2.noarch.rpm thunderbird-da-10.0.12-1.mga2.noarch.rpm thunderbird-de-10.0.12-1.mga2.noarch.rpm thunderbird-el-10.0.12-1.mga2.noarch.rpm thunderbird-en_GB-10.0.12-1.mga2.noarch.rpm thunderbird-es_AR-10.0.12-1.mga2.noarch.rpm thunderbird-es_ES-10.0.12-1.mga2.noarch.rpm thunderbird-et-10.0.12-1.mga2.noarch.rpm thunderbird-eu-10.0.12-1.mga2.noarch.rpm thunderbird-fi-10.0.12-1.mga2.noarch.rpm thunderbird-fr-10.0.12-1.mga2.noarch.rpm thunderbird-fy-10.0.12-1.mga2.noarch.rpm thunderbird-ga-10.0.12-1.mga2.noarch.rpm thunderbird-gd-10.0.12-1.mga2.noarch.rpm thunderbird-gl-10.0.12-1.mga2.noarch.rpm thunderbird-he-10.0.12-1.mga2.noarch.rpm thunderbird-hu-10.0.12-1.mga2.noarch.rpm thunderbird-id-10.0.12-1.mga2.noarch.rpm thunderbird-is-10.0.12-1.mga2.noarch.rpm thunderbird-it-10.0.12-1.mga2.noarch.rpm thunderbird-ja-10.0.12-1.mga2.noarch.rpm thunderbird-ko-10.0.12-1.mga2.noarch.rpm thunderbird-lt-10.0.12-1.mga2.noarch.rpm thunderbird-nb_NO-10.0.12-1.mga2.noarch.rpm thunderbird-nl-10.0.12-1.mga2.noarch.rpm thunderbird-nn_NO-10.0.12-1.mga2.noarch.rpm thunderbird-pa_IN-10.0.12-1.mga2.noarch.rpm thunderbird-pl-10.0.12-1.mga2.noarch.rpm thunderbird-pt_BR-10.0.12-1.mga2.noarch.rpm thunderbird-pt_PT-10.0.12-1.mga2.noarch.rpm thunderbird-ro-10.0.12-1.mga2.noarch.rpm thunderbird-ru-10.0.12-1.mga2.noarch.rpm thunderbird-si-10.0.12-1.mga2.noarch.rpm thunderbird-sk-10.0.12-1.mga2.noarch.rpm thunderbird-sl-10.0.12-1.mga2.noarch.rpm thunderbird-sq-10.0.12-1.mga2.noarch.rpm thunderbird-sv_SE-10.0.12-1.mga2.noarch.rpm thunderbird-ta_LK-10.0.12-1.mga2.noarch.rpm thunderbird-tr-10.0.12-1.mga2.noarch.rpm thunderbird-uk-10.0.12-1.mga2.noarch.rpm thunderbird-vi-10.0.12-1.mga2.noarch.rpm thunderbird-zh_CN-10.0.12-1.mga2.noarch.rpm thunderbird-zh_TW-10.0.12-1.mga2.noarch.rpm SRPMS: thunderbird-10.0.12-1.mga2.src.rpm thunderbird-l10n-10.0.12-1.mga2.src.rpm References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0744 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0746 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0748 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0750 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0753 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0754 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0758 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0759 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0762 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0766 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0767 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0769 http://www.mozilla.org/security/announce/2013/mfsa2013-01... http://www.mozilla.org/security/announce/2013/mfsa2013-02... http://www.mozilla.org/security/announce/2013/mfsa2013-04... http://www.mozilla.org/security/announce/2013/mfsa2013-05... http://www.mozilla.org/security/announce/2013/mfsa2013-09... http://www.mozilla.org/security/announce/2013/mfsa2013-11... http://www.mozilla.org/security/announce/2013/mfsa2013-12... http://www.mozilla.org/security/announce/2013/mfsa2013-15... http://www.mozilla.org/security/announce/2013/mfsa2013-16... http://www.mozilla.org/security/announce/2013/mfsa2013-17... https://rhn.redhat.com/errata/RHSA-2013-0145.html https://bugs.mageia.org/show_bug.cgi?id=8767 https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds