Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the way Thunderbird processes certain malformed
Javascript code. A malicious web page could cause the execution of
Javascript code in such a way that could cause Thunderbird to crash or
execute arbitrary code as the user running Thunderbird. JavaScript support
is disabled by default in Thunderbird; this issue is not exploitable
without enabling JavaScript. (CVE-2006-6498, CVE-2006-6501, CVE-2006-6502,
CVE-2006-6503, CVE-2006-6504)
Several flaws were found in the way Thunderbird renders web pages. A
malicious web page could cause the browser to crash or possibly execute
arbitrary code as the user running Thunderbird. (CVE-2006-6497)
A heap based buffer overflow flaw was found in the way Thunderbird parses
the Content-Type mail header. A malicious mail message could cause the
Thunderbird client to crash or possibly execute arbitrary code as the user
running Thunderbird. (CVE-2006-6505)
Users of Thunderbird are advised to apply this update, which contains
Thunderbird version 1.5.0.9 that corrects these issues.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
RedHat | 4 | s390 | thunderbird | < 1.5.0.9-0.1.el4 | thunderbird-1.5.0.9-0.1.el4.s390.rpm |
RedHat | 4 | ia64 | thunderbird | < 1.5.0.9-0.1.el4 | thunderbird-1.5.0.9-0.1.el4.ia64.rpm |
RedHat | 4 | x86_64 | thunderbird | < 1.5.0.9-0.1.el4 | thunderbird-1.5.0.9-0.1.el4.x86_64.rpm |
RedHat | 4 | src | thunderbird | < 1.5.0.9-0.1.el4 | thunderbird-1.5.0.9-0.1.el4.src.rpm |
RedHat | 4 | ppc | thunderbird | < 1.5.0.9-0.1.el4 | thunderbird-1.5.0.9-0.1.el4.ppc.rpm |
RedHat | 4 | s390x | thunderbird | < 1.5.0.9-0.1.el4 | thunderbird-1.5.0.9-0.1.el4.s390x.rpm |
RedHat | 4 | i386 | thunderbird | < 1.5.0.9-0.1.el4 | thunderbird-1.5.0.9-0.1.el4.i386.rpm |