what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Secunia Security Advisory 22055

Secunia Security Advisory 22055
Posted Sep 22, 2006
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Ubuntu has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to conduct man-in-the-middle and cross-site scripting attacks, bypass certain security restrictions and compromise a user's system.

tags | advisory, vulnerability, xss
systems | linux, ubuntu
SHA-256 | cef500ab6995da0b499bafad5ba7590209fc38938df125eff1a309fb9cf39dfc

Secunia Security Advisory 22055

Change Mirror Download


----------------------------------------------------------------------

Want to work within IT-Security?

Secunia is expanding its team of highly skilled security experts.
We will help with relocation and obtaining a work permit.

Currently the following type of positions are available:
http://secunia.com/quality_assurance_analyst/
http://secunia.com/web_application_security_specialist/
http://secunia.com/hardcore_disassembler_and_reverse_engineer/

----------------------------------------------------------------------

TITLE:
Ubuntu update for mozilla-thunderbird

SECUNIA ADVISORY ID:
SA22055

VERIFY ADVISORY:
http://secunia.com/advisories/22055/

CRITICAL:
Highly critical

IMPACT:
Security Bypass, Cross Site Scripting, DoS, System access

WHERE:
>From remote

OPERATING SYSTEM:
Ubuntu Linux 5.10
http://secunia.com/product/6606/

DESCRIPTION:
Ubuntu has issued an update for mozilla-thunderbird. This fixes some
vulnerabilities, which can be exploited by malicious people to
conduct man-in-the-middle and cross-site scripting attacks, bypass
certain security restrictions and compromise a user's system.

For more information:
SA21228
SA21939

SOLUTION:
Apply updated packages:

-- Ubuntu 5.10 --

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird_1.5.0.7-0ubuntu0.5.10.diff.gz
Size/MD5: 451765 f226c2d1fb27ff7d1901563c0e7ae6aa
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird_1.5.0.7-0ubuntu0.5.10.dsc
Size/MD5: 960 33f4c6cf8f964b3bbf0cb7bf2a9b3a41
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird_1.5.0.7.orig.tar.gz
Size/MD5: 35412353 4e43a174c53adf09382a4f959b86abe6
http://security.ubuntu.com/ubuntu/pool/main/e/enigmail/enigmail_0.94-0ubuntu0.5.10.diff.gz
Size/MD5: 20864 3aee73c8c9d639372dc3f28a5f145324
http://security.ubuntu.com/ubuntu/pool/main/e/enigmail/enigmail_0.94-0ubuntu0.5.10.dsc
Size/MD5: 785 25206240fb199da5bbb5ab080600b0d5
http://security.ubuntu.com/ubuntu/pool/main/e/enigmail/enigmail_0.94.orig.tar.gz
Size/MD5: 3126659 7e34cbe51f5a1faca2e26fa0edfd6a06
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-ca/mozilla-thunderbird-locale-ca_1.5-ubuntu5.10.dsc
Size/MD5: 598 1d99f1f9e4dee5e65e3783a5f97dd263
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-ca/mozilla-thunderbird-locale-ca_1.5-ubuntu5.10.tar.gz
Size/MD5: 194758 ef06a28aee74c384480bc0ab4b4b884c
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-de/mozilla-thunderbird-locale-de_1.5-ubuntu5.10.dsc
Size/MD5: 596 4fa9a37540021ec258720b4870bb96d7
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-de/mozilla-thunderbird-locale-de_1.5-ubuntu5.10.tar.gz
Size/MD5: 169713 7c1002115108c1ed63d270a8d679b039
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-fr/mozilla-thunderbird-locale-fr_1.5-ubuntu5.10.dsc
Size/MD5: 599 ef565a49f01984cf671542e909fc9585
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-fr/mozilla-thunderbird-locale-fr_1.5-ubuntu5.10.tar.gz
Size/MD5: 204062 8a1ef43eccb78e45895bd1bff458d0fe
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-it/mozilla-thunderbird-locale-it_1.5-ubuntu5.10.dsc
Size/MD5: 601 90e8f323e3bc9a5f46c4a97a509cfc93
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-it/mozilla-thunderbird-locale-it_1.5-ubuntu5.10.tar.gz
Size/MD5: 158517 cddf397975e97c0dbd7152f387655303
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-nl/mozilla-thunderbird-locale-nl_1.5-ubuntu5.10.dsc
Size/MD5: 596 b4d740d0e33dde12c978b8f7385f690d
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-nl/mozilla-thunderbird-locale-nl_1.5-ubuntu5.10.tar.gz
Size/MD5: 195416 fc5bc7dc7388131564bdbbd16ab10b93
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-pl/mozilla-thunderbird-locale-pl_1.5-ubuntu5.10.dsc
Size/MD5: 632 de741d572f4ab22f99793aa3cfbe20e3
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-pl/mozilla-thunderbird-locale-pl_1.5-ubuntu5.10.tar.gz
Size/MD5: 192583 5cf008def5286ed0054a0a5015607cf7
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-uk/mozilla-thunderbird-locale-uk_1.5-ubuntu5.10.dsc
Size/MD5: 589 330958f8cb291d10cdc0196768233ad0
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-uk/mozilla-thunderbird-locale-uk_1.5-ubuntu5.10.tar.gz
Size/MD5: 11499 dd66aaa9efadb412e3122657a2da25fa

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-ca/mozilla-thunderbird-locale-ca_1.5-ubuntu5.10_all.deb
Size/MD5: 189666 473e996d047d43f6dd7bec92d53cfa03
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-de/mozilla-thunderbird-locale-de_1.5-ubuntu5.10_all.deb
Size/MD5: 167484 20623a5c44dc5b2196da99eed084b8b8
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-fr/mozilla-thunderbird-locale-fr_1.5-ubuntu5.10_all.deb
Size/MD5: 197384 6a49d6b1d63c6fbf5a5ba552916d933a
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-it/mozilla-thunderbird-locale-it_1.5-ubuntu5.10_all.deb
Size/MD5: 153016 c1e4f810878dfb4ea7a98422e566bab7
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-nl/mozilla-thunderbird-locale-nl_1.5-ubuntu5.10_all.deb
Size/MD5: 195206 a2b2c8189f2bdbd52ba207e467404e18
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-pl/mozilla-thunderbird-locale-pl_1.5-ubuntu5.10_all.deb
Size/MD5: 186030 4d1c2103ee676e569c0feb553161107c
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird-locale-uk/mozilla-thunderbird-locale-uk_1.5-ubuntu5.10_all.deb
Size/MD5: 11860 088e396b7bc681bbf773232e1fc62b7d

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird-dev_1.5.0.7-0ubuntu0.5.10_amd64.deb
Size/MD5: 3523522 a76de9534e4f7062f6ca1089ba190b95
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird-inspector_1.5.0.7-0ubuntu0.5.10_amd64.deb
Size/MD5: 190306 74bda8f95e40506db2eb9522ff5a0aad
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird-typeaheadfind_1.5.0.7-0ubuntu0.5.10_amd64.deb
Size/MD5: 55528 5bba85b882ef03b8d6abf6a30ee87581
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird_1.5.0.7-0ubuntu0.5.10_amd64.deb
Size/MD5: 11976232 2d6fd4f9dfc0f141d9deb7321d8c3d4f
http://security.ubuntu.com/ubuntu/pool/main/e/enigmail/mozilla-thunderbird-enigmail_0.94-0ubuntu0.5.10_amd64.deb
Size/MD5: 334962 a958117e8d86e698a1e0486169086c96

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird-dev_1.5.0.7-0ubuntu0.5.10_i386.deb
Size/MD5: 3516366 c0f3feae48b1c6aa62f3423279be2725
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird-inspector_1.5.0.7-0ubuntu0.5.10_i386.deb
Size/MD5: 183652 664776fcb3fcc35bb58e7edbc3a5492b
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird-typeaheadfind_1.5.0.7-0ubuntu0.5.10_i386.deb
Size/MD5: 51154 d35f0c9b0ad24a3ecb16c3ce29cd5427
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird_1.5.0.7-0ubuntu0.5.10_i386.deb
Size/MD5: 10282110 16ef30b246a84f1872129c6ecd9d0a75
http://security.ubuntu.com/ubuntu/pool/main/e/enigmail/mozilla-thunderbird-enigmail_0.94-0ubuntu0.5.10_i386.deb
Size/MD5: 322874 fdfb2bb51b8b360734169d9a6362bfb7

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird-dev_1.5.0.7-0ubuntu0.5.10_powerpc.deb
Size/MD5: 3520948 5d6db52b3aa4ea827dae5d2d1d42ade1
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird-inspector_1.5.0.7-0ubuntu0.5.10_powerpc.deb
Size/MD5: 187002 2998ab2a9287273f9b80ad7ce9ba5829
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird-typeaheadfind_1.5.0.7-0ubuntu0.5.10_powerpc.deb
Size/MD5: 54712 73da47232d65de50c846c0d287ccd4ca
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-thunderbird/mozilla-thunderbird_1.5.0.7-0ubuntu0.5.10_powerpc.deb
Size/MD5: 11523006 c8d86889f60569a3d578241e63f89f11
http://security.ubuntu.com/ubuntu/pool/main/e/enigmail/mozilla-thunderbird-enigmail_0.94-0ubuntu0.5.10_powerpc.deb
Size/MD5: 326204 f25574cc20db03e78e0879b941a36600

ORIGINAL ADVISORY:
http://www.ubuntu.com/usn/usn-350-1

OTHER REFERENCES:
SA21228:
http://secunia.com/advisories/21228/

SA21939:
http://secunia.com/advisories/21939/

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/


Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close