Debian DSA-1574-1 : icedove - several vulnerabilities

High Nessus Plugin ID 32308

Synopsis

The remote Debian host is missing a security-related update.

Description

# This shares a lot of text with dsa-1532.wml, dsa-1534.wml, dsa-1535.wml

Several remote vulnerabilities have been discovered in the Icedove mail client, an unbranded version of the Thunderbird client. The Common Vulnerabilities and Exposures project identifies the following problems :

- CVE-2008-1233 'moz_bug_r_a4' discovered that variants of CVE-2007-3738 and CVE-2007-5338 allow the execution of arbitrary code through XPCNativeWrapper.

- CVE-2008-1234 'moz_bug_r_a4' discovered that insecure handling of event handlers could lead to cross-site scripting.

- CVE-2008-1235 Boris Zbarsky, Johnny Stenback and 'moz_bug_r_a4' discovered that incorrect principal handling could lead to cross-site scripting and the execution of arbitrary code.

- CVE-2008-1236 Tom Ferris, Seth Spitzer, Martin Wargers, John Daggett and Mats Palmgren discovered crashes in the layout engine, which might allow the execution of arbitrary code.

- CVE-2008-1237 'georgi', 'tgirmann' and Igor Bukanov discovered crashes in the JavaScript engine, which might allow the execution of arbitrary code.

Solution

Upgrade the icedove packages.

For the stable distribution (etch), these problems have been fixed in version 1.5.0.13+1.5.0.15b.dfsg1+prepatch080417a-0etch1.

See Also

https://security-tracker.debian.org/tracker/CVE-2008-1233

https://security-tracker.debian.org/tracker/CVE-2007-3738

https://security-tracker.debian.org/tracker/CVE-2007-5338

https://security-tracker.debian.org/tracker/CVE-2008-1234

https://security-tracker.debian.org/tracker/CVE-2008-1235

https://security-tracker.debian.org/tracker/CVE-2008-1236

https://security-tracker.debian.org/tracker/CVE-2008-1237

https://www.debian.org/security/2008/dsa-1574

Plugin Details

Severity: High

ID: 32308

File Name: debian_DSA-1574.nasl

Version: 1.18

Type: local

Agent: unix

Published: 2008/05/13

Updated: 2019/08/02

Dependencies: 12634

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:icedove, cpe:/o:debian:debian_linux:4.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2008/05/12

Reference Information

CVE: CVE-2008-1233, CVE-2008-1234, CVE-2008-1235, CVE-2008-1236, CVE-2008-1237

BID: 28448

DSA: 1574

CWE: 79, 94, 399