Vulnerability   
Search   
    Search 191973 CVE descriptions
and 86218 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.702797
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 2797-1 (icedove - several vulnerabilities)
Summary:Multiple security issues have been found in Icedove, Debian's version of;the Mozilla Thunderbird mail and news client. Multiple memory safety;errors, and other implementation errors may lead to the execution of;arbitrary code.;;The Icedove version in the oldstable distribution (squeeze) is no longer;supported with full security updates. However, it should be noted that;almost all security issues in Icedove stem from the included browser engine.;These security problems only affect Icedove if scripting and HTML mails;are enabled. If there are security issues specific to Icedove (e.g. a;hypothetical buffer overflow in the IMAP implementation) we'll make an;effort to backport such fixes to oldstable.
Description:Summary:
Multiple security issues have been found in Icedove, Debian's version of
the Mozilla Thunderbird mail and news client. Multiple memory safety
errors, and other implementation errors may lead to the execution of
arbitrary code.

The Icedove version in the oldstable distribution (squeeze) is no longer
supported with full security updates. However, it should be noted that
almost all security issues in Icedove stem from the included browser engine.
These security problems only affect Icedove if scripting and HTML mails
are enabled. If there are security issues specific to Icedove (e.g. a
hypothetical buffer overflow in the IMAP implementation) we'll make an
effort to backport such fixes to oldstable.

Affected Software/OS:
icedove on Debian Linux

Solution:
For the stable distribution (wheezy), these problems have been fixed in
version 17.0.10-1~
deb7u1.

For the unstable distribution (sid), these problems have been fixed in
version 17.0.10-1.

We recommend that you upgrade your icedove packages.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-5595
BugTraq ID: 63421
http://www.securityfocus.com/bid/63421
Debian Security Information: DSA-2788 (Google Search)
http://www.debian.org/security/2013/dsa-2788
Debian Security Information: DSA-2797 (Google Search)
http://www.debian.org/security/2013/dsa-2797
https://security.gentoo.org/glsa/201504-01
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18694
RedHat Security Advisories: RHSA-2013:1476
http://rhn.redhat.com/errata/RHSA-2013-1476.html
RedHat Security Advisories: RHSA-2013:1480
http://rhn.redhat.com/errata/RHSA-2013-1480.html
SuSE Security Announcement: SUSE-SU-2013:1678 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00014.html
SuSE Security Announcement: openSUSE-SU-2013:1633 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.html
SuSE Security Announcement: openSUSE-SU-2013:1634 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00006.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-5597
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19277
Common Vulnerability Exposure (CVE) ID: CVE-2013-5599
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19315
Common Vulnerability Exposure (CVE) ID: CVE-2013-5602
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19293
Common Vulnerability Exposure (CVE) ID: CVE-2013-5604
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19091
Common Vulnerability Exposure (CVE) ID: CVE-2013-5601
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18495
Common Vulnerability Exposure (CVE) ID: CVE-2013-5600
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19172
Common Vulnerability Exposure (CVE) ID: CVE-2013-5590
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19001
CopyrightCopyright (C) 2013 Greenbone Networks GmbH http://greenbone.net

This is only one of 86218 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2020 E-Soft Inc. All rights reserved.