Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Netflix outside the USA - in Linux & with Tunlr
· Enhanced Mitigation Experience Toolkit 4.0
· Intel Haswell HD Graphics 4600 vs. AMD Radeon Graphics On Linux
· DSA 2709-1: wireshark security update
· Simulator Provides Early Look at iOS 7 on the iPad
· AMD A10-6800K Cracks 8.00 GHz Mark and more
· Ubuntu 13.10 Release Schedule
· PHP 5.5.0 RC3 for Debian 7.0 Wheezy
· Windows 8.1 screenshots leaked, redesigns showcased
· DSA 2708-1: fail2ban security update

Upcoming News
· The SSD Review has Posted a New Article!
· News: AMD's A10-6800K and A10-6700 'Richland' APUs reviewed
· AllPuter.com product launch: 20X Super Long Range Telescope for Galaxy Note 2 Photography
· Intel DZ87KLT-75K "Kinsley Thunderbolt" Motherboard Review @ HiTech Legion
· Corsair Carbide Air 540 ATX Cube Chassis Review
· REVIEW: Diamond Radeon HD 7790 @ PureOverclock
· SanDisk Extreme II 240 GB SSD Review @ OCC
· Ubuntu Weekly Newsletter Issue 321
· Boxes 3.9.3
· [security-announce] SUSE-SU-2013:1022-2: important: Security update for Linux kernel

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· Building a new PC: how EXACTLY to install USB mouse?
by: joyask43
on: 2013-06-09 14:36
6 replies, 2588 views

· Packet CD
by: natalieksh5
on: 2013-06-06 14:19
4 replies, 3420 views

· THE SIMS 2 DIRECTX 9.0C ERROR MESSAGE!! HELP! URGENT!!
by: tandrask34
on: 2013-06-05 14:06
28 replies, 93150 views

· Hello
by: barryherne
on: 2013-06-05 13:09
0 replies, 167 views

· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6883 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » October 2012 » [RHSA-2012:1413-01] Important: thunderbird security update

[RHSA-2012:1413-01] Important: thunderbird security update

Posted by Philipp Esselbach on: 10/30/2012 10:58 AM [ Print | 0 comment(s) ]

A thunderbird security update has been released for Red Hat Enterprise Linux 5 and 6




=====================================================================
Red Hat Security Advisory

Synopsis: Important: thunderbird security update
Advisory ID: RHSA-2012:1413-01
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2012-1413.html
Issue date: 2012-10-29
CVE Names: CVE-2012-4194 CVE-2012-4195 CVE-2012-4196
=====================================================================

1. Summary:

An updated thunderbird package that fixes multiple security issues is now
available for Red Hat Enterprise Linux 5 and 6.

The Red Hat Security Response Team has rated this update as having
important security impact. Common Vulnerability Scoring System (CVSS) base
scores, which give detailed severity ratings, are available for each
vulnerability from the CVE links in the References section.

2. Relevant releases/architectures:

RHEL Optional Productivity Applications (v. 5 server) - i386, x86_64
Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64
Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64
Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64

3. Description:

Mozilla Thunderbird is a standalone mail and newsgroup client.

Multiple flaws were found in the location object implementation in
Thunderbird. Malicious content could be used to perform cross-site
scripting attacks, bypass the same-origin policy, or cause Thunderbird to
execute arbitrary code. (CVE-2012-4194, CVE-2012-4195, CVE-2012-4196)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Mariusz Mlynski, moz_bug_r_a4, and Antoine
Delignat-Lavaud as the original reporters of these issues.

Note: None of the issues in this advisory can be exploited by a
specially-crafted HTML mail message as JavaScript is disabled by default
for mail messages. They could be exploited another way in Thunderbird, for
example, when viewing the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 10.0.10 ESR, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.

4. Solution:

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258

5. Bugs fixed (http://bugzilla.redhat.com/):

869893 - CVE-2012-4194 CVE-2012-4195 CVE-2012-4196 Mozilla: Fixes for Location object issues (MFSA 2012-90)

6. Package List:

Red Hat Enterprise Linux Desktop (v. 5 client):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/thunderbird-10.0.10-1.el5_8.src.rpm

i386:
thunderbird-10.0.10-1.el5_8.i386.rpm
thunderbird-debuginfo-10.0.10-1.el5_8.i386.rpm

x86_64:
thunderbird-10.0.10-1.el5_8.x86_64.rpm
thunderbird-debuginfo-10.0.10-1.el5_8.x86_64.rpm

RHEL Optional Productivity Applications (v. 5 server):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Server/en/os/SRPMS/thunderbird-10.0.10-1.el5_8.src.rpm

i386:
thunderbird-10.0.10-1.el5_8.i386.rpm
thunderbird-debuginfo-10.0.10-1.el5_8.i386.rpm

x86_64:
thunderbird-10.0.10-1.el5_8.x86_64.rpm
thunderbird-debuginfo-10.0.10-1.el5_8.x86_64.rpm

Red Hat Enterprise Linux Desktop (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Client/en/os/SRPMS/thunderbird-10.0.10-1.el6_3.src.rpm

i386:
thunderbird-10.0.10-1.el6_3.i686.rpm
thunderbird-debuginfo-10.0.10-1.el6_3.i686.rpm

x86_64:
thunderbird-10.0.10-1.el6_3.x86_64.rpm
thunderbird-debuginfo-10.0.10-1.el6_3.x86_64.rpm

Red Hat Enterprise Linux Server Optional (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Server/en/os/SRPMS/thunderbird-10.0.10-1.el6_3.src.rpm

i386:
thunderbird-10.0.10-1.el6_3.i686.rpm
thunderbird-debuginfo-10.0.10-1.el6_3.i686.rpm

ppc64:
thunderbird-10.0.10-1.el6_3.ppc64.rpm
thunderbird-debuginfo-10.0.10-1.el6_3.ppc64.rpm

s390x:
thunderbird-10.0.10-1.el6_3.s390x.rpm
thunderbird-debuginfo-10.0.10-1.el6_3.s390x.rpm

x86_64:
thunderbird-10.0.10-1.el6_3.x86_64.rpm
thunderbird-debuginfo-10.0.10-1.el6_3.x86_64.rpm

Red Hat Enterprise Linux Workstation (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Workstation/en/os/SRPMS/thunderbird-10.0.10-1.el6_3.src.rpm

i386:
thunderbird-10.0.10-1.el6_3.i686.rpm
thunderbird-debuginfo-10.0.10-1.el6_3.i686.rpm

x86_64:
thunderbird-10.0.10-1.el6_3.x86_64.rpm
thunderbird-debuginfo-10.0.10-1.el6_3.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/#package

7. References:

https://www.redhat.com/security/data/cve/CVE-2012-4194.html
https://www.redhat.com/security/data/cve/CVE-2012-4195.html
https://www.redhat.com/security/data/cve/CVE-2012-4196.html
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2012 Red Hat, Inc.


[RHSA-2012:1413-01] Important: thunderbird security update


Bookmark and Share

« Cooler Master CMSTORM Recon, Skorpion, & Speed RXL Review · Windows Phone 8 smartphone buying guide »

Linux Compatible » News » October 2012 » [RHSA-2012:1413-01] Important: thunderbird security update
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition