Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ USN-2904-1: Thunderbird vulnerabilities

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š USN-2904-1: Thunderbird vulnerabilities


๐Ÿ’ก Newskategorie: Unix Server
๐Ÿ”— Quelle: ubuntu.com

Ubuntu Security Notice USN-2904-1

8th March, 2016

thunderbird vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 15.10
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

Several security issues were fixed in Thunderbird.

Software description

  • thunderbird - Mozilla Open Source mail and newsgroup client

Details

Karthikeyan Bhargavan and Gaetan Leurent discovered that NSS incorrectly
allowed MD5 to be used for TLS 1.2 connections. If a remote attacker were
able to perform a man-in-the-middle attack, this flaw could be exploited to
view sensitive information. (CVE-2015-7575)

Yves Younan discovered that graphite2 incorrectly handled certain malformed
fonts. If a user were tricked into opening a specially crafted website in a
browsing context, an attacker could potentially exploit this to cause a
denial of service via application crash, or execute arbitary code with the
privileges of the user invoking Thunderbird. (CVE-2016-1523)

Bob Clary, Christian Holler, Nils Ohlmeier, Gary Kwong, Jesse Ruderman,
Carsten Book, and Randell Jesup discovered multiple memory safety issues
in Thunderbird. If a user were tricked in to opening a specially crafted
website in a browsing context, an attacker could potentially exploit these
to cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Thunderbird. (CVE-2016-1930)

Aki Helin discovered a buffer overflow when rendering WebGL content in
some circumstances. If a user were tricked in to opening a specially
crafted website in a browsing context, an attacker could potentially
exploit this to cause a denial of service via application crash, or
execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2016-1935)

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 15.10:
thunderbird 1:38.6.0+build1-0ubuntu0.15.10.1
Ubuntu 14.04 LTS:
thunderbird 1:38.6.0+build1-0ubuntu0.14.04.1
Ubuntu 12.04 LTS:
thunderbird 1:38.6.0+build1-0ubuntu0.12.04.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

References

CVE-2015-7575, CVE-2016-1523, CVE-2016-1930, CVE-2016-1935

...













๐Ÿ“Œ USN-2819-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-2859-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-2934-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-2934-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3165-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3278-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-4647-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-4736-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-4936-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-2973-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3073-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3023-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3073-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3112-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3141-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-2819-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-2859-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-2973-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3490-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3023-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3545-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3112-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3141-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3233-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-4028-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3321-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3416-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3436-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-4045-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-3529-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-4064-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-4150-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-4202-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-4241-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

๐Ÿ“Œ USN-4328-1: Thunderbird vulnerabilities


๐Ÿ“ˆ 18.68 Punkte

matomo