Debian DSA-3601-1 : icedove - security update
Critical Nessus Plugin ID 91614
SynopsisThe remote Debian host is missing a security-related update.
DescriptionMultiple security issues have been found in Icedove, Debian's version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service.
Debian follows the extended support releases (ESR) of Thunderbird.
Support for the 38.x series has ended, so starting with this update we're now following the 45.x releases.
SolutionUpgrade the icedove packages.
For the stable distribution (jessie), this problem has been fixed in version 1:45.1.0-1~deb8u1.