|
|
Log in / Subscribe / Register

thunderbird: multiple vulnerabilities

Package(s):thunderbird CVE #(s):CVE-2011-0070 CVE-2011-0071 CVE-2011-0073 CVE-2011-0074 CVE-2011-0075 CVE-2011-0077 CVE-2011-0078 CVE-2011-0080 CVE-2011-0081
Created:April 29, 2011 Updated:July 19, 2011
Description: From the Red Hat advisory:

Several flaws were found in the processing of malformed HTML content. An HTML mail message containing malicious content could possibly lead to arbitrary code execution with the privileges of the user running Thunderbird. (CVE-2011-0080, CVE-2011-0081)

An arbitrary memory write flaw was found in the way Thunderbird handled out-of-memory conditions. If all memory was consumed when a user viewed a malicious HTML mail message, it could possibly lead to arbitrary code execution with the privileges of the user running Thunderbird. (CVE-2011-0078)

An integer overflow flaw was found in the way Thunderbird handled the HTML frameset tag. An HTML mail message with a frameset tag containing large values for the "rows" and "cols" attributes could trigger this flaw, possibly leading to arbitrary code execution with the privileges of the user running Thunderbird. (CVE-2011-0077)

A flaw was found in the way Thunderbird handled the HTML iframe tag. An HTML mail message with an iframe tag containing a specially-crafted source address could trigger this flaw, possibly leading to arbitrary code execution with the privileges of the user running Thunderbird. (CVE-2011-0075)

A flaw was found in the way Thunderbird displayed multiple marquee elements. A malformed HTML mail message could cause Thunderbird to execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2011-0074)

A flaw was found in the way Thunderbird handled the nsTreeSelection element. Malformed content could cause Thunderbird to execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2011-0073)

A directory traversal flaw was found in the Thunderbird resource:// protocol handler. Malicious content could cause Thunderbird to access arbitrary files accessible to the user running Thunderbird. (CVE-2011-0071)

A double free flaw was found in the way Thunderbird handled "application/http-index-format" documents. A malformed HTTP response could cause Thunderbird to execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2011-0070)

Alerts:
openSUSE openSUSE-SU-2014:1100-1 Firefox 2014-09-09
Gentoo 201301-01 firefox 2013-01-07
Fedora FEDORA-2011-9139 thunderbird 2011-07-08
Slackware SSA:2011-189-02 thunderbird 2011-07-11
Ubuntu USN-1122-3 thunderbird 2011-06-06
Fedora FEDORA-2011-6205 thunderbird 2011-04-29
Fedora FEDORA-2011-6215 gnome-python2-extras 2011-04-29
Fedora FEDORA-2011-6215 perl-Gtk2-MozEmbed 2011-04-29
Red Hat RHSA-2011:0475-01 thunderbird 2011-04-28
Fedora FEDORA-2011-6205 xulrunner 2011-04-29
openSUSE openSUSE-SU-2011:0437-1 mozilla-xulrunner192 2011-05-06
Fedora FEDORA-2011-6215 mozvoikko 2011-04-29
Fedora FEDORA-2011-6215 gnome-web-photo 2011-04-29
Fedora FEDORA-2011-6215 galeon 2011-04-29
Fedora FEDORA-2011-6215 thunderbird 2011-04-29
CentOS CESA-2011:0471 firefox 2011-04-29
CentOS CESA-2011:0474 thunderbird 2011-04-29
Red Hat RHSA-2011:0471-01 firefox 2011-04-28
Fedora FEDORA-2011-6205 galeon 2011-04-29
Fedora FEDORA-2011-6205 gnome-web-photo 2011-04-29
Fedora FEDORA-2011-6205 perl-Gtk2-MozEmbed 2011-04-29
Fedora FEDORA-2011-6205 gnome-python2-extras 2011-04-29
Slackware SSA:2011-122-02 thunderbird 2011-05-03
Fedora FEDORA-2011-6215 xulrunner 2011-04-29
Debian DSA-2228-1 iceweasel 2011-05-01
Debian DSA-2227-1 iceape 2011-04-30
Ubuntu USN-1121-1 firefox 2011-04-30
CentOS CESA-2011:0473 seamonkey 2011-04-29
Fedora FEDORA-2011-6245 seamonkey 2011-04-29
Fedora FEDORA-2011-6258 seamonkey 2011-04-29
Fedora FEDORA-2011-6205 mozvoikko 2011-04-29
Fedora FEDORA-2011-6205 firefox 2011-04-29
Ubuntu USN-1122-2 thunderbird 2011-05-05
Ubuntu USN-1122-1 thunderbird 2011-05-05
SUSE SUSE-SA:2011:022 MozillaFirefox,seamonkey,MozillaThunderbird 2011-05-05
Slackware SSA:2011-122-03 seamonkey 2011-05-03
Ubuntu USN-1112-1 firefox, firefox-3.0, firefox-3.5, xulrunner-1.9.2 2011-04-29
CentOS CESA-2011:0471 firefox 2011-04-29
Red Hat RHSA-2011:0473-01 seamonkey 2011-04-28
Debian DSA-2235-1 icedove 2011-05-10
Fedora FEDORA-2011-6215 firefox 2011-04-29
Mandriva MDVSA-2011:080 mozilla-thunderbird 2011-05-01
Mandriva MDVSA-2011:079 firefox 2011-04-30
Ubuntu USN-1123-1 xulrunner-1.9.1 2011-04-30
CentOS CESA-2011:0474 thunderbird 2011-04-29
Red Hat RHSA-2011:0474-01 thunderbird 2011-04-28

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds