[USN-6214-1] Thunderbird vulnerabilities
nishit.majithia at canonical.com
Tue Jul 11 06:35:39 UTC 2023
Ubuntu Security Notice USN-6214-1
July 11, 2023
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Several security issues were fixed in Thunderbird.
- thunderbird: Mozilla Open Source mail and newsgroup client
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-34414, CVE-2023-34416,
CVE-2023-37201, CVE-2023-37202, CVE-2023-37207, CVE-2023-37211)
P Umar Farooq discovered that Thunderbird did not properly provide warning
when opening Diagcab files. If a user were tricked into opening a
malicicous Diagcab file, an attacker could execute arbitrary code.
The problem can be corrected by updating your system to the following
Ubuntu 22.04 LTS:
Ubuntu 20.04 LTS:
In general, a standard system update will make all the necessary changes.
CVE-2023-34414, CVE-2023-34416, CVE-2023-37201, CVE-2023-37202,
CVE-2023-37207, CVE-2023-37208, CVE-2023-37211
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 659 bytes
Desc: not available
More information about the ubuntu-security-announce