USN-3112-1: Thunderbird vulnerabilities
USN-3112-1: Thunderbird vulnerabilities Ubuntu Security Notice USN-3112-1 27th October, 2016 thunderbird vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in Thunderbird. Software description thunderbird – Mozilla Open Source mail and newsgroup client Details Catalin Dumitru discovered that URLs of resources loaded after anavigation start could be leaked to the following page via the ResourceTiming API. If a user were tricked in to opening a specially craftedwebsite in a browsing context, an attacker could potentially exploit thisto obtain sensitive information. (CVE-2016-5250) Christoph Diehl, Andrew McCreight, Dan Minor, Byron Campen, Jon Coppeard,Steve Fink, Tyson Smith, and Carsten Book discovered multiple memorysafety issues in Thunderbird. If a user were tricked in to opening aspecially crafted message, an attacker could potentially exploit these [ more… ]