Debian DSA-2528-1 : icedove - several vulnerabilities

critical Nessus Plugin ID 61537

Synopsis

The remote Debian host is missing a security-related update.

Description

Several vulnerabilities were discovered in Icedove, Debian's version of the Mozilla Thunderbird mail and news client.

- CVE-2012-1948 Multiple unspecified vulnerabilities in the browser engine were fixed.

- CVE-2012-1950 The underlying browser engine allows address bar spoofing through drag-and-drop.

- CVE-2012-1954 A use-after-free vulnerability in the nsDocument::AdoptNode function allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code.

- CVE-2012-1967 An error in the implementation of the JavaScript sandbox allows execution of JavaScript code with improper privileges using javascript: URLs.

Solution

Upgrade the icedove packages.

For the stable distribution (squeeze), these problems have been fixed in version 3.0.11-1+squeeze12.

See Also

https://security-tracker.debian.org/tracker/CVE-2012-1948

https://security-tracker.debian.org/tracker/CVE-2012-1950

https://security-tracker.debian.org/tracker/CVE-2012-1954

https://security-tracker.debian.org/tracker/CVE-2012-1967

https://packages.debian.org/source/squeeze/icedove

https://www.debian.org/security/2012/dsa-2528

Plugin Details

Severity: Critical

ID: 61537

File Name: debian_DSA-2528.nasl

Version: 1.14

Type: local

Agent: unix

Published: 8/15/2012

Updated: 1/11/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:icedove, cpe:/o:debian:debian_linux:6.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 8/14/2012

Reference Information

CVE: CVE-2012-1948, CVE-2012-1950, CVE-2012-1954, CVE-2012-1967

BID: 54573, 54578, 54580, 54585

DSA: 2528