Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.12.2023.6405.1
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-6405-1)
Summary:The remote host is missing an update for the 'thunderbird' package(s) announced via the USN-6405-1 advisory.
Description:Summary:
The remote host is missing an update for the 'thunderbird' package(s) announced via the USN-6405-1 advisory.

Vulnerability Insight:
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-4057, CVE-2023-4577,
CVE-2023-4578, CVE-2023-4583, CVE-2023-4585, CVE-2023-5169, CVE-2023-5171,
CVE-2023-5176)

Andrew McCreight discovered that Thunderbird did not properly manage during
the worker lifecycle. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2023-3600)

Harveer Singh discovered that Thunderbird did not store push notifications
in private browsing mode in encrypted form. An attacker could potentially
exploit this issue to obtain sensitive information. (CVE-2023-4580)

Clement Lecigne discovered that Thunderbird did not properly manage memory
when handling VP8 media stream. An attacker-controlled VP8 media stream
could lead to a heap buffer overflow in the content process, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2023-5217)

Affected Software/OS:
'thunderbird' package(s) on Ubuntu 20.04, Ubuntu 22.04, Ubuntu 23.04.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2023-3600
https://bugzilla.mozilla.org/show_bug.cgi?id=1839703
https://www.mozilla.org/security/advisories/mfsa2023-26/
https://www.mozilla.org/security/advisories/mfsa2023-27/
Common Vulnerability Exposure (CVE) ID: CVE-2023-4057
Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1
https://bugzilla.mozilla.org/show_bug.cgi?id=1841682
https://www.mozilla.org/security/advisories/mfsa2023-29/
https://www.mozilla.org/security/advisories/mfsa2023-31/
https://www.mozilla.org/security/advisories/mfsa2023-33/
Common Vulnerability Exposure (CVE) ID: CVE-2023-4577
https://bugzilla.mozilla.org/show_bug.cgi?id=1847397
https://www.mozilla.org/security/advisories/mfsa2023-34/
https://www.mozilla.org/security/advisories/mfsa2023-36/
https://www.mozilla.org/security/advisories/mfsa2023-38/
Common Vulnerability Exposure (CVE) ID: CVE-2023-4578
https://bugzilla.mozilla.org/show_bug.cgi?id=1839007
Common Vulnerability Exposure (CVE) ID: CVE-2023-4580
https://bugzilla.mozilla.org/show_bug.cgi?id=1843046
Common Vulnerability Exposure (CVE) ID: CVE-2023-4583
https://bugzilla.mozilla.org/show_bug.cgi?id=1842030
Common Vulnerability Exposure (CVE) ID: CVE-2023-4585
Memory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1751583%2C1841082%2C1847904%2C1848999
Common Vulnerability Exposure (CVE) ID: CVE-2023-5169
Debian Security Information: DSA-5506 (Google Search)
https://www.debian.org/security/2023/dsa-5506
Debian Security Information: DSA-5513 (Google Search)
https://www.debian.org/security/2023/dsa-5513
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AY642Z6JZODQJE7Z62CFREVUHEGCXGPD/
https://bugzilla.mozilla.org/show_bug.cgi?id=1846685
https://www.mozilla.org/security/advisories/mfsa2023-41/
https://www.mozilla.org/security/advisories/mfsa2023-42/
https://www.mozilla.org/security/advisories/mfsa2023-43/
https://lists.debian.org/debian-lts-announce/2023/09/msg00034.html
https://lists.debian.org/debian-lts-announce/2023/10/msg00015.html
Common Vulnerability Exposure (CVE) ID: CVE-2023-5171
https://bugzilla.mozilla.org/show_bug.cgi?id=1851599
Common Vulnerability Exposure (CVE) ID: CVE-2023-5176
Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1836353%2C1842674%2C1843824%2C1843962%2C1848890%2C1850180%2C1850983%2C1851195
Common Vulnerability Exposure (CVE) ID: CVE-2023-5217
Debian Security Information: DSA-5508 (Google Search)
https://www.debian.org/security/2023/dsa-5508
Debian Security Information: DSA-5509 (Google Search)
https://www.debian.org/security/2023/dsa-5509
Debian Security Information: DSA-5510 (Google Search)
https://www.debian.org/security/2023/dsa-5510
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4MFWDFJSSIFKWKNOCTQCFUNZWAXUCSS4/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/55YVCZNAVY3Y5E4DWPWMX2SPKZ2E5SOV/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BCVSHVX2RFBU3RMCUFSATVQEJUFD4Q63/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CWEJYS5NC7KVFYU3OAMPKQDYN6JQGVK6/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TE7F54W5O5RS4ZMAAC7YK3CZWQXIDSKB/
http://seclists.org/fulldisclosure/2023/Oct/12
http://seclists.org/fulldisclosure/2023/Oct/16
https://security.gentoo.org/glsa/202310-04
https://security.gentoo.org/glsa/202401-34
https://arstechnica.com/security/2023/09/new-0-day-in-chrome-and-firefox-is-likely-to-plague-other-software/
https://bugzilla.redhat.com/show_bug.cgi?id=2241191
https://github.com/webmproject/libvpx/commit/3fbd1dca6a4d2dad332a2110d646e4ffef36d590
https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282
https://github.com/webmproject/libvpx/tags
https://pastebin.com/TdkC4pDv
https://security-tracker.debian.org/tracker/CVE-2023-5217
https://stackdiary.com/google-discloses-a-webm-vp8-bug-tracked-as-cve-2023-5217/
https://twitter.com/maddiestone/status/1707163313711497266
https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/
https://www.openwall.com/lists/oss-security/2023/09/28/5
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html
https://crbug.com/1486441
https://lists.debian.org/debian-lts-announce/2023/09/msg00038.html
https://lists.debian.org/debian-lts-announce/2023/10/msg00001.html
http://www.openwall.com/lists/oss-security/2023/09/28/5
http://www.openwall.com/lists/oss-security/2023/09/28/6
http://www.openwall.com/lists/oss-security/2023/09/29/1
http://www.openwall.com/lists/oss-security/2023/09/29/11
http://www.openwall.com/lists/oss-security/2023/09/29/12
http://www.openwall.com/lists/oss-security/2023/09/29/14
http://www.openwall.com/lists/oss-security/2023/09/29/2
http://www.openwall.com/lists/oss-security/2023/09/29/9
http://www.openwall.com/lists/oss-security/2023/09/29/7
http://www.openwall.com/lists/oss-security/2023/09/30/4
http://www.openwall.com/lists/oss-security/2023/09/30/2
http://www.openwall.com/lists/oss-security/2023/09/30/3
http://www.openwall.com/lists/oss-security/2023/09/30/5
http://www.openwall.com/lists/oss-security/2023/09/30/1
http://www.openwall.com/lists/oss-security/2023/10/01/5
http://www.openwall.com/lists/oss-security/2023/10/01/2
http://www.openwall.com/lists/oss-security/2023/10/01/1
http://www.openwall.com/lists/oss-security/2023/10/02/6
http://www.openwall.com/lists/oss-security/2023/10/03/11
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.