Description: | Summary: The remote host is missing an update for the Debian 'icedove' package(s) announced via the DSA-1696-1 advisory.
Vulnerability Insight: Several remote vulnerabilities have been discovered in the Icedove mail client, an unbranded version of the Thunderbird mail client. The Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2008-0016
Justin Schuh, Tom Cross and Peter Williams discovered a buffer overflow in the parser for UTF-8 URLs, which may lead to the execution of arbitrary code. (MFSA 2008-37)
CVE-2008-1380
It was discovered that crashes in the Javascript engine could potentially lead to the execution of arbitrary code. (MFSA 2008-20)
CVE-2008-3835
'moz_bug_r_a4' discovered that the same-origin check in nsXMLDocument::OnChannelRedirect() could be bypassed. (MFSA 2008-38)
CVE-2008-4058
'moz_bug_r_a4' discovered a vulnerability which can result in Chrome privilege escalation through XPCNativeWrappers. (MFSA 2008-41)
CVE-2008-4059
'moz_bug_r_a4' discovered a vulnerability which can result in Chrome privilege escalation through XPCNativeWrappers. (MFSA 2008-41)
CVE-2008-4060
Olli Pettay and 'moz_bug_r_a4' discovered a Chrome privilege escalation vulnerability in XSLT handling. (MFSA 2008-41)
CVE-2008-4061
Jesse Ruderman discovered a crash in the layout engine, which might allow the execution of arbitrary code. (MFSA 2008-42)
CVE-2008-4062
Igor Bukanov, Philip Taylor, Georgi Guninski and Antoine Labour discovered crashes in the Javascript engine, which might allow the execution of arbitrary code. (MFSA 2008-42)
CVE-2008-4065
Dave Reed discovered that some Unicode byte order marks are stripped from Javascript code before execution, which can result in code being executed, which were otherwise part of a quoted string. (MFSA 2008-43)
CVE-2008-4067
It was discovered that a directory traversal allows attackers to read arbitrary files via a certain character. (MFSA 2008-44)
CVE-2008-4068
It was discovered that a directory traversal allows attackers to bypass security restrictions and obtain sensitive information. (MFSA 2008-44)
CVE-2008-4070
It was discovered that a buffer overflow could be triggered via a long header in a news article, which could lead to arbitrary code execution. (MFSA 2008-46)
CVE-2008-4582
Liu Die Yu and Boris Zbarsky discovered an information leak through local shortcut files. (MFSA 2008-47, MFSA 2008-59)
CVE-2008-5012
Georgi Guninski, Michal Zalewski and Chris Evan discovered that the canvas element could be used to bypass same-origin restrictions. (MFSA 2008-48)
CVE-2008-5014
Jesse Ruderman discovered that a programming error in the window.__proto__.__proto__ object could lead to arbitrary code execution. (MFSA 2008-50)
CVE-2008-5017
It was discovered that crashes in the layout engine could lead to arbitrary code execution. (MFSA 2008-52)
CVE-2008-5018
It was discovered that crashes in the Javascript engine could lead to arbitrary code execution. (MFSA 2008-52)
CVE-2008-5021
It was discovered that a crash in the ... [Please see the references for more information on the vulnerabilities]
Affected Software/OS: 'icedove' package(s) on Debian 4.
Solution: Please install the updated package(s).
CVSS Score: 10.0
CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
|