Scientific Linux Security Update : thunderbird on SL4.x, SL5.x i386/x86_64

Critical Nessus Plugin ID 60975


The remote Scientific Linux host is missing a security update.


Several flaws were found in the processing of malformed HTML content.
Malicious HTML content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2011-0051, CVE-2011-0053)

Note: JavaScript support is disabled by default in Thunderbird. The above issues are not exploitable unless JavaScript is enabled.

All running instances of Thunderbird must be restarted for the update to take effect.


Update the affected thunderbird package.

See Also

Plugin Details

Severity: Critical

ID: 60975

File Name: sl_20110301_thunderbird_on_SL4_x.nasl

Version: $Revision: 1.1 $

Type: local

Agent: unix

Published: 2012/08/01

Modified: 2012/08/01

Dependencies: 12634

Risk Information

Risk Factor: Critical


Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 2011/03/01

Reference Information

CVE: CVE-2011-0051, CVE-2011-0053