Lucene search

K
debianDebianDEBIAN:BSA-046:D9C0C
HistoryAug 26, 2011 - 8:23 p.m.

[BSA-046] Security Update for icedove

2011-08-2620:23:59
lists.debian.org
31

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.8

Percentile

98.3%

Christoph Göhre uploaded new packages for icedove which fixed the following
security problems:

CVE-2011-0084

"regenrecht" discovered that incorrect pointer handling in the SVG
processing code could lead to the execution of arbitrary code.

CVE-2011-2378

"regenrecht" discovered that incorrect memory management in DOM
processing could lead to the execution of arbitrary code.

CVE-2011-2981

"moz_bug_r_a_4" discovered a Chrome privilege escalation
vulnerability in the event handler code.

CVE-2011-2982

Gary Kwong, Igor Bukanov, Nils and Bob Clary discovered memory
corruption bugs, which may lead to the execution of arbitrary code.

CVE-2011-2983

"shutdown" discovered an information leak in the handling of
RegExp.input.

CVE-2011-2984

"moz_bug_r_a4" discovered a Chrome privilege escalation vulnerability.

For the squeeze-backports distribution, this problem have been fixed in
version 3.1.12-1~bpo60+1.

For the testing distribution (wheezy), this problem has been fixed in
version 3.1.12-1.

For the unstable distribution (sid), this problem has been fixed in
version 3.1.12-1.

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.8

Percentile

98.3%