USN-3073-1: Thunderbird vulnerabilities
Christian Holler, Carsten Book, Gary Kwong, Jesse Ruderman, Andrew McCreight, and Phil Ringnalda discovered multiple memory safety issues in Thunderbird. If a user were tricked in to opening a specially crafted message, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code. (CVE-2016-2836)
Affected Software
Event History
Frequently Asked Questions
What is the title of the vulnerability?
USN-3073-1: Thunderbird vulnerabilities
Who discovered the vulnerabilities?
Christian Holler, Carsten Book, Gary Kwong, Jesse Ruderman, Andrew McCreight, and Phil Ringnalda
What is the impact of the vulnerability?
An attacker could potentially cause a denial of service via a specially crafted message.
Which versions of Thunderbird are affected?
Versions 1:45.3.0+build1-0ubuntu0.16.04.2, 1:45.3.0+build1-0ubuntu0.14.04.4, and 1:45.3.0+build1-0ubuntu0.12.04.1 of Thunderbird on Ubuntu are affected.
Where can I find more information about the vulnerability?
More information about the vulnerability can be found at the following links: [CVE-2016-2836](https://ubuntu.com/security/CVE-2016-2836), [USN-3044-1](https://ubuntu.com/security/notices/USN-3044-1), [Launchpad](https://launchpad.net/ubuntu/+source/thunderbird/1:45.3.0+build1-0ubuntu0.16.04.2)