Ubuntu Security Notice (C) 2008-2016 Canonical, Inc. / NASL script (C) 2009-2016 Tenable Network Security, Inc.
The remote Ubuntu host is missing one or more security-related
It was discovered that the same-origin check in Thunderbird could be
opening a malicious website, an attacker may be able to execute
Several problems were discovered in the browser engine of Thunderbird.
execute code with chrome privileges. (CVE-2008-4058, CVE-2008-4059,
Drew Yao, David Maciejak and other Mozilla developers found several
problems in the browser engine of Thunderbird. If a user had
an attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2008-4061, CVE-2008-4062, CVE-2008-4063, CVE-2008-4064)
processing certain BOM characters. An attacker could exploit this to
bypass script filters and perform cross-site scripting attacks if a
Gareth Heyes discovered a flaw in the HTML parser of Thunderbird. If a
web page, an attacker could bypass script filtering and perform
cross-site scripting attacks. (CVE-2008-4066)
Boris Zbarsky and Georgi Guninski independently discovered flaws in
the resource: protocol. An attacker could exploit this to perform
directory traversal, read information about the system, and prompt the
user to save information in a file. (CVE-2008-4067, CVE-2008-4068)
Georgi Guninski discovered that Thunderbird improperly handled
cancelled newsgroup messages. If a user opened a crafted newsgroup
message, an attacker could cause a buffer overrun and potentially
execute arbitrary code with the privileges of the user invoking the
Note that Tenable Network Security has extracted the preceding
description block directly from the Ubuntu security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.
Update the affected packages.
Risk factor :
Critical / CVSS Base Score : 10.0
Family: Ubuntu Local Security Checks
Nessus Plugin ID: 37910 ()
Get Nessus Professional to scan unlimited IPs, run compliance checks & moreBuy Nessus Professional Now