Home→Descriptions→SA50460
| Secunia ID | |
| CVE-ID |
CVE-2012-1956, CVE-2012-1970, CVE-2012-1971, CVE-2012-1972, CVE-2012-1973, CVE-2012-1974, CVE-2012-1975, CVE-2012-1976, CVE-2012-3956, CVE-2012-3957, CVE-2012-3958, CVE-2012-3959, CVE-2012-3960, CVE-2012-3961, CVE-2012-3962, CVE-2012-3963, CVE-2012-3964, CVE-2012-3966, CVE-2012-3967, CVE-2012-3968, CVE-2012-3969, CVE-2012-3970, CVE-2012-3971, CVE-2012-3972, CVE-2012-3975, CVE-2012-3978, CVE-2012-3980 |
| Release Date |
31 Aug 2012 |
| Last Change |
01 Oct 2012 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. Cross-Site ScriptingCross-Site Scripting vulnerabilities allow a third party to manipulate the content or behaviour of a web application in a user's browser, without compromising the underlying system. Different Cross-Site Scripting related vulnerabilities are also classified under this category, including "script insertion" and "cross-site request forgery". Cross-Site Scripting vulnerabilities are often used against specific users of a website to steal their credentials or to conduct spoofing attacks. Exposure of sensitive informationVulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote. |
| Description |
Ubuntu has issued an update for thunderbird. This fixes multiple vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, and compromise a user's system. For more information: |
| Solution |
Apply updated packages. -- Ubuntu 12.04 LTS -- -- Ubuntu 11.10 -- -- Ubuntu 11.04 -- -- Ubuntu 10.04 LTS -- NOTE: New packages released for thunderbird to fix a regression introduced in previous update. -- Ubuntu 12.04 LTS -- -- Ubuntu 11.10 -- -- Ubuntu 11.04 -- -- Ubuntu 10.04 LTS -- |
| Original Advisory |
USN-1551-1: USN-1551-2: |