Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.842682
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-2904-1)
Summary:The remote host is missing an update for the 'thunderbird' package(s) announced via the USN-2904-1 advisory.
Description:Summary:
The remote host is missing an update for the 'thunderbird' package(s) announced via the USN-2904-1 advisory.

Vulnerability Insight:
Karthikeyan Bhargavan and Gaetan Leurent discovered that NSS incorrectly
allowed MD5 to be used for TLS 1.2 connections. If a remote attacker were
able to perform a machine-in-the-middle attack, this flaw could be exploited to
view sensitive information. (CVE-2015-7575)

Yves Younan discovered that graphite2 incorrectly handled certain malformed
fonts. If a user were tricked into opening a specially crafted website in a
browsing context, an attacker could potentially exploit this to cause a
denial of service via application crash, or execute arbitrary code with the
privileges of the user invoking Thunderbird. (CVE-2016-1523)

Bob Clary, Christian Holler, Nils Ohlmeier, Gary Kwong, Jesse Ruderman,
Carsten Book, and Randell Jesup discovered multiple memory safety issues
in Thunderbird. If a user were tricked in to opening a specially crafted
website in a browsing context, an attacker could potentially exploit these
to cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Thunderbird. (CVE-2016-1930)

Aki Helin discovered a buffer overflow when rendering WebGL content in
some circumstances. If a user were tricked in to opening a specially
crafted website in a browsing context, an attacker could potentially
exploit this to cause a denial of service via application crash, or
execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2016-1935)

Affected Software/OS:
'thunderbird' package(s) on Ubuntu 12.04, Ubuntu 14.04, Ubuntu 15.10.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-7575
1034541
http://www.securitytracker.com/id/1034541
1036467
http://www.securitytracker.com/id/1036467
79684
http://www.securityfocus.com/bid/79684
91787
http://www.securityfocus.com/bid/91787
DSA-3436
http://www.debian.org/security/2016/dsa-3436
DSA-3437
http://www.debian.org/security/2016/dsa-3437
DSA-3457
http://www.debian.org/security/2016/dsa-3457
DSA-3458
http://www.debian.org/security/2016/dsa-3458
DSA-3465
http://www.debian.org/security/2016/dsa-3465
DSA-3491
http://www.debian.org/security/2016/dsa-3491
DSA-3688
http://www.debian.org/security/2016/dsa-3688
GLSA-201701-46
https://security.gentoo.org/glsa/201701-46
GLSA-201706-18
https://security.gentoo.org/glsa/201706-18
GLSA-201801-15
https://security.gentoo.org/glsa/201801-15
RHSA-2016:0049
http://rhn.redhat.com/errata/RHSA-2016-0049.html
RHSA-2016:0050
http://rhn.redhat.com/errata/RHSA-2016-0050.html
RHSA-2016:0053
http://rhn.redhat.com/errata/RHSA-2016-0053.html
RHSA-2016:0054
http://rhn.redhat.com/errata/RHSA-2016-0054.html
RHSA-2016:0055
http://rhn.redhat.com/errata/RHSA-2016-0055.html
RHSA-2016:0056
http://rhn.redhat.com/errata/RHSA-2016-0056.html
RHSA-2016:1430
https://access.redhat.com/errata/RHSA-2016:1430
SUSE-SU-2016:0256
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.html
SUSE-SU-2016:0265
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.html
SUSE-SU-2016:0269
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.html
USN-2863-1
http://www.ubuntu.com/usn/USN-2863-1
USN-2864-1
http://www.ubuntu.com/usn/USN-2864-1
USN-2865-1
http://www.ubuntu.com/usn/USN-2865-1
USN-2866-1
http://www.ubuntu.com/usn/USN-2866-1
USN-2884-1
http://www.ubuntu.com/usn/USN-2884-1
USN-2904-1
http://www.ubuntu.com/usn/USN-2904-1
http://www.mozilla.org/security/announce/2015/mfsa2015-150.html
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
https://bugzilla.mozilla.org/show_bug.cgi?id=1158489
https://developer.mozilla.org/docs/Mozilla/Projects/NSS/NSS_3.20.2_release_notes
https://security.netapp.com/advisory/ntap-20160225-0001/
openSUSE-SU-2015:2405
http://lists.opensuse.org/opensuse-updates/2015-12/msg00139.html
openSUSE-SU-2016:0007
http://lists.opensuse.org/opensuse-updates/2016-01/msg00005.html
openSUSE-SU-2016:0161
http://lists.opensuse.org/opensuse-updates/2016-01/msg00058.html
openSUSE-SU-2016:0162
http://lists.opensuse.org/opensuse-updates/2016-01/msg00059.html
openSUSE-SU-2016:0263
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.html
openSUSE-SU-2016:0268
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.html
openSUSE-SU-2016:0270
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html
openSUSE-SU-2016:0272
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.html
openSUSE-SU-2016:0279
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.html
openSUSE-SU-2016:0307
http://lists.opensuse.org/opensuse-updates/2016-02/msg00007.html
openSUSE-SU-2016:0308
http://lists.opensuse.org/opensuse-updates/2016-02/msg00008.html
openSUSE-SU-2016:0488
http://lists.opensuse.org/opensuse-updates/2016-02/msg00101.html
openSUSE-SU-2016:0605
http://lists.opensuse.org/opensuse-updates/2016-02/msg00166.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-1523
BugTraq ID: 82991
http://www.securityfocus.com/bid/82991
Debian Security Information: DSA-3477 (Google Search)
http://www.debian.org/security/2016/dsa-3477
Debian Security Information: DSA-3479 (Google Search)
http://www.debian.org/security/2016/dsa-3479
Debian Security Information: DSA-3491 (Google Search)
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184623.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177520.html
https://security.gentoo.org/glsa/201605-06
https://security.gentoo.org/glsa/201701-35
https://security.gentoo.org/glsa/201701-63
http://blog.talosintel.com/2016/02/vulnerability-spotlight-libgraphite.html
RedHat Security Advisories: RHSA-2016:0197
http://rhn.redhat.com/errata/RHSA-2016-0197.html
RedHat Security Advisories: RHSA-2016:0258
http://rhn.redhat.com/errata/RHSA-2016-0258.html
RedHat Security Advisories: RHSA-2016:0594
http://rhn.redhat.com/errata/RHSA-2016-0594.html
http://www.securitytracker.com/id/1035017
SuSE Security Announcement: SUSE-SU-2016:0554 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00053.html
SuSE Security Announcement: SUSE-SU-2016:0564 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00055.html
SuSE Security Announcement: SUSE-SU-2016:0779 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00052.html
SuSE Security Announcement: openSUSE-SU-2016:0791 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00058.html
SuSE Security Announcement: openSUSE-SU-2016:0875 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00088.html
http://www.ubuntu.com/usn/USN-2902-1
Common Vulnerability Exposure (CVE) ID: CVE-2016-1930
BugTraq ID: 81953
http://www.securityfocus.com/bid/81953
Debian Security Information: DSA-3457 (Google Search)
RedHat Security Advisories: RHSA-2016:0071
http://rhn.redhat.com/errata/RHSA-2016-0071.html
http://www.securitytracker.com/id/1034825
SuSE Security Announcement: SUSE-SU-2016:0338 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00010.html
SuSE Security Announcement: openSUSE-SU-2016:0306 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.html
SuSE Security Announcement: openSUSE-SU-2016:0309 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.html
SuSE Security Announcement: openSUSE-SU-2016:0310 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00003.html
SuSE Security Announcement: openSUSE-SU-2016:0488 (Google Search)
SuSE Security Announcement: openSUSE-SU-2016:0492 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-02/msg00105.html
http://www.ubuntu.com/usn/USN-2880-1
http://www.ubuntu.com/usn/USN-2880-2
Common Vulnerability Exposure (CVE) ID: CVE-2016-1935
BugTraq ID: 81952
http://www.securityfocus.com/bid/81952
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.