Synopsis
Moderate: thunderbird security update
Type/Severity
Security Advisory: Moderate
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
Updated thunderbird packages that fix several security bugs are now
available for Red Hat Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Description
Mozilla Thunderbird is a standalone mail and newsgroup client.
Several flaws were found in the way Thunderbird processed certain malformed
JavaScript code. A malicious HTML email message containing JavaScript code
could cause Thunderbird to crash or potentially execute arbitrary code as
the user running Thunderbird. JavaScript support is disabled by default in
Thunderbird; these issues are not exploitable unless the user has enabled
JavaScript. (CVE-2007-3089, CVE-2007-3734, CVE-2007-3735, CVE-2007-3736,
CVE-2007-3737, CVE-2007-3738)
Users of Thunderbird are advised to upgrade to these erratum packages,
which contain backported patches that correct these issues.
Solution
Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.
This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188
Affected Products
-
Red Hat Enterprise Linux Server 5 x86_64
-
Red Hat Enterprise Linux Server 5 i386
-
Red Hat Enterprise Linux Server 4 x86_64
-
Red Hat Enterprise Linux Server 4 ia64
-
Red Hat Enterprise Linux Server 4 i386
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 4.5 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 4.5 ia64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 4.5 i386
-
Red Hat Enterprise Linux Workstation 5 x86_64
-
Red Hat Enterprise Linux Workstation 5 i386
-
Red Hat Enterprise Linux Workstation 4 x86_64
-
Red Hat Enterprise Linux Workstation 4 ia64
-
Red Hat Enterprise Linux Workstation 4 i386
-
Red Hat Enterprise Linux Desktop 5 x86_64
-
Red Hat Enterprise Linux Desktop 5 i386
-
Red Hat Enterprise Linux Desktop 4 x86_64
-
Red Hat Enterprise Linux Desktop 4 i386
-
Red Hat Enterprise Linux for IBM z Systems 4 s390x
-
Red Hat Enterprise Linux for IBM z Systems 4 s390
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 4.5 s390x
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 4.5 s390
-
Red Hat Enterprise Linux for Power, big endian 4 ppc
-
Red Hat Enterprise Linux for Power, big endian - Extended Update Support 4.5 ppc
-
Red Hat Enterprise Linux Server from RHUI 5 x86_64
-
Red Hat Enterprise Linux Server from RHUI 5 i386
Fixes
-
BZ - 248518
- CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux Server 5
SRPM |
thunderbird-1.5.0.12-3.el5.src.rpm
|
SHA-256: e1ca304e6d0ed7ecef56f57431547507120d126d092dd5fb3cb785e1199b7c81 |
x86_64 |
thunderbird-1.5.0.12-3.el5.x86_64.rpm
|
SHA-256: 3259d36ca5b4c483fe359be479faa2a9262ede0e078405a5a6dac1f441b7128b |
i386 |
thunderbird-1.5.0.12-3.el5.i386.rpm
|
SHA-256: fedb12a3373687aa552187bbac7cee06a1c7275a27ddfc0840daadde90182959 |
Red Hat Enterprise Linux Server 4
SRPM |
thunderbird-1.5.0.12-0.3.el4.src.rpm
|
SHA-256: 20d812f495d6c653b663fe194779aac880ad9bd1cce1fa8ed4679e51599fb289 |
x86_64 |
thunderbird-1.5.0.12-0.3.el4.x86_64.rpm
|
SHA-256: 68a32fdf0e772bba298d515ed7b0aedc5af92422e4fecd043379602ba501265b |
thunderbird-1.5.0.12-0.3.el4.x86_64.rpm
|
SHA-256: 68a32fdf0e772bba298d515ed7b0aedc5af92422e4fecd043379602ba501265b |
ia64 |
thunderbird-1.5.0.12-0.3.el4.ia64.rpm
|
SHA-256: 621b8bd702162c380d9d4610fd4e19ead66e54d57eea0e2ea4154f92d8f0dd83 |
thunderbird-1.5.0.12-0.3.el4.ia64.rpm
|
SHA-256: 621b8bd702162c380d9d4610fd4e19ead66e54d57eea0e2ea4154f92d8f0dd83 |
i386 |
thunderbird-1.5.0.12-0.3.el4.i386.rpm
|
SHA-256: a343a09b3b395dff03c46ee1870dda4a990ee30adaac3511084bb8b72451f58b |
thunderbird-1.5.0.12-0.3.el4.i386.rpm
|
SHA-256: a343a09b3b395dff03c46ee1870dda4a990ee30adaac3511084bb8b72451f58b |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 4.5
SRPM |
thunderbird-1.5.0.12-0.3.el4.src.rpm
|
SHA-256: 20d812f495d6c653b663fe194779aac880ad9bd1cce1fa8ed4679e51599fb289 |
x86_64 |
thunderbird-1.5.0.12-0.3.el4.x86_64.rpm
|
SHA-256: 68a32fdf0e772bba298d515ed7b0aedc5af92422e4fecd043379602ba501265b |
thunderbird-1.5.0.12-0.3.el4.x86_64.rpm
|
SHA-256: 68a32fdf0e772bba298d515ed7b0aedc5af92422e4fecd043379602ba501265b |
ia64 |
thunderbird-1.5.0.12-0.3.el4.ia64.rpm
|
SHA-256: 621b8bd702162c380d9d4610fd4e19ead66e54d57eea0e2ea4154f92d8f0dd83 |
thunderbird-1.5.0.12-0.3.el4.ia64.rpm
|
SHA-256: 621b8bd702162c380d9d4610fd4e19ead66e54d57eea0e2ea4154f92d8f0dd83 |
i386 |
thunderbird-1.5.0.12-0.3.el4.i386.rpm
|
SHA-256: a343a09b3b395dff03c46ee1870dda4a990ee30adaac3511084bb8b72451f58b |
thunderbird-1.5.0.12-0.3.el4.i386.rpm
|
SHA-256: a343a09b3b395dff03c46ee1870dda4a990ee30adaac3511084bb8b72451f58b |
Red Hat Enterprise Linux Workstation 5
SRPM |
thunderbird-1.5.0.12-3.el5.src.rpm
|
SHA-256: e1ca304e6d0ed7ecef56f57431547507120d126d092dd5fb3cb785e1199b7c81 |
x86_64 |
thunderbird-1.5.0.12-3.el5.x86_64.rpm
|
SHA-256: 3259d36ca5b4c483fe359be479faa2a9262ede0e078405a5a6dac1f441b7128b |
i386 |
thunderbird-1.5.0.12-3.el5.i386.rpm
|
SHA-256: fedb12a3373687aa552187bbac7cee06a1c7275a27ddfc0840daadde90182959 |
Red Hat Enterprise Linux Workstation 4
SRPM |
thunderbird-1.5.0.12-0.3.el4.src.rpm
|
SHA-256: 20d812f495d6c653b663fe194779aac880ad9bd1cce1fa8ed4679e51599fb289 |
x86_64 |
thunderbird-1.5.0.12-0.3.el4.x86_64.rpm
|
SHA-256: 68a32fdf0e772bba298d515ed7b0aedc5af92422e4fecd043379602ba501265b |
ia64 |
thunderbird-1.5.0.12-0.3.el4.ia64.rpm
|
SHA-256: 621b8bd702162c380d9d4610fd4e19ead66e54d57eea0e2ea4154f92d8f0dd83 |
i386 |
thunderbird-1.5.0.12-0.3.el4.i386.rpm
|
SHA-256: a343a09b3b395dff03c46ee1870dda4a990ee30adaac3511084bb8b72451f58b |
Red Hat Enterprise Linux Desktop 5
SRPM |
thunderbird-1.5.0.12-3.el5.src.rpm
|
SHA-256: e1ca304e6d0ed7ecef56f57431547507120d126d092dd5fb3cb785e1199b7c81 |
x86_64 |
thunderbird-1.5.0.12-3.el5.x86_64.rpm
|
SHA-256: 3259d36ca5b4c483fe359be479faa2a9262ede0e078405a5a6dac1f441b7128b |
i386 |
thunderbird-1.5.0.12-3.el5.i386.rpm
|
SHA-256: fedb12a3373687aa552187bbac7cee06a1c7275a27ddfc0840daadde90182959 |
Red Hat Enterprise Linux Desktop 4
SRPM |
thunderbird-1.5.0.12-0.3.el4.src.rpm
|
SHA-256: 20d812f495d6c653b663fe194779aac880ad9bd1cce1fa8ed4679e51599fb289 |
x86_64 |
thunderbird-1.5.0.12-0.3.el4.x86_64.rpm
|
SHA-256: 68a32fdf0e772bba298d515ed7b0aedc5af92422e4fecd043379602ba501265b |
i386 |
thunderbird-1.5.0.12-0.3.el4.i386.rpm
|
SHA-256: a343a09b3b395dff03c46ee1870dda4a990ee30adaac3511084bb8b72451f58b |
Red Hat Enterprise Linux for IBM z Systems 4
SRPM |
thunderbird-1.5.0.12-0.3.el4.src.rpm
|
SHA-256: 20d812f495d6c653b663fe194779aac880ad9bd1cce1fa8ed4679e51599fb289 |
s390x |
thunderbird-1.5.0.12-0.3.el4.s390x.rpm
|
SHA-256: 81c7aedcdeb17256634c4c0869c444fee05e092c522a97fa4db9b028250a9191 |
s390 |
thunderbird-1.5.0.12-0.3.el4.s390.rpm
|
SHA-256: 518588cf6d945f1cb2a47cba4416a4407c5009644eafd432abfb6cecfbc216b5 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 4.5
SRPM |
thunderbird-1.5.0.12-0.3.el4.src.rpm
|
SHA-256: 20d812f495d6c653b663fe194779aac880ad9bd1cce1fa8ed4679e51599fb289 |
s390x |
thunderbird-1.5.0.12-0.3.el4.s390x.rpm
|
SHA-256: 81c7aedcdeb17256634c4c0869c444fee05e092c522a97fa4db9b028250a9191 |
s390 |
thunderbird-1.5.0.12-0.3.el4.s390.rpm
|
SHA-256: 518588cf6d945f1cb2a47cba4416a4407c5009644eafd432abfb6cecfbc216b5 |
Red Hat Enterprise Linux for Power, big endian 4
SRPM |
thunderbird-1.5.0.12-0.3.el4.src.rpm
|
SHA-256: 20d812f495d6c653b663fe194779aac880ad9bd1cce1fa8ed4679e51599fb289 |
ppc |
thunderbird-1.5.0.12-0.3.el4.ppc.rpm
|
SHA-256: b9da395852051d25c39d9f7b97019d53699c5e9ff31d69b0119d44584a83adcd |
Red Hat Enterprise Linux for Power, big endian - Extended Update Support 4.5
SRPM |
thunderbird-1.5.0.12-0.3.el4.src.rpm
|
SHA-256: 20d812f495d6c653b663fe194779aac880ad9bd1cce1fa8ed4679e51599fb289 |
ppc |
thunderbird-1.5.0.12-0.3.el4.ppc.rpm
|
SHA-256: b9da395852051d25c39d9f7b97019d53699c5e9ff31d69b0119d44584a83adcd |
Red Hat Enterprise Linux Server from RHUI 5
SRPM |
thunderbird-1.5.0.12-3.el5.src.rpm
|
SHA-256: e1ca304e6d0ed7ecef56f57431547507120d126d092dd5fb3cb785e1199b7c81 |
x86_64 |
thunderbird-1.5.0.12-3.el5.x86_64.rpm
|
SHA-256: 3259d36ca5b4c483fe359be479faa2a9262ede0e078405a5a6dac1f441b7128b |
i386 |
thunderbird-1.5.0.12-3.el5.i386.rpm
|
SHA-256: fedb12a3373687aa552187bbac7cee06a1c7275a27ddfc0840daadde90182959 |