USN-7066-1: Thunderbird vulnerability
Published Oct 14, 2024
·Updated
Damien Schaeffer discovered that Thunderbird did not properly manage certain memory operations when processing content in the Animation timelines. An attacker could potentially exploit this issue to achieve arbitrary code execution.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/thunderbird<1:115.16.0+build2-0ubuntu0.22.04.1
1:115.16.0+build2-0ubuntu0.22.04.1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/thunderbird<1:115.16.0+build2-0ubuntu0.20.04.1
1:115.16.0+build2-0ubuntu0.20.04.1
Ubuntu Ubuntu=20.04
Event History
Oct 14, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7066-1?
The severity of USN-7066-1 is considered high due to the potential for arbitrary code execution.
2
How do I fix USN-7066-1?
To fix USN-7066-1, update Thunderbird to version 1:115.16.0+build2-0ubuntu0.22.04.1 or a later version.
3
What versions of Thunderbird are affected by USN-7066-1?
Versions of Thunderbird prior to 1:115.16.0+build2-0ubuntu0.22.04.1 and 1:115.16.0+build2-0ubuntu0.20.04.1 are affected by USN-7066-1.
4
Can USN-7066-1 be exploited remotely?
Yes, USN-7066-1 can potentially be exploited remotely to execute arbitrary code.
5
Which Ubuntu versions are impacted by USN-7066-1?
Ubuntu 22.04 and 20.04 are the impacted versions associated with USN-7066-1.