RHEL 5 / 6 : thunderbird (RHSA-2012:1351)

medium Nessus Plugin ID 62473

Synopsis

The remote Red Hat host is missing one or more security updates for thunderbird.

Description

The remote Redhat Enterprise Linux 5 / 6 host has a package installed that is affected by multiple vulnerabilities as referenced in the RHSA-2012:1351 advisory.

- Mozilla: Location object can be shadowed using Object.defineProperty (MFSA 2012-59) (CVE-2012-1956)

- Mozilla: Miscellaneous memory safety hazards (rv:10.0.8) (MFSA 2012-74) (CVE-2012-3982)

- Mozilla: Some DOMWindowUtils methods bypass security checks (MFSA 2012-77) (CVE-2012-3986)

- Mozilla: DOS and crash with full screen and history navigation (MFSA 2012-79) (CVE-2012-3988)

- Mozilla: Use-after-free in the IME State Manager (MFSA 2012-87) (CVE-2012-3990)

- Mozilla: GetProperty function can bypass security checks (MFSA 2012-81) (CVE-2012-3991)

- Mozilla: Spoofing and script injection through location.hash (MFSA 2012-84) (CVE-2012-3992)

- Mozilla: Chrome Object Wrapper (COW) does not disallow acces to privileged functions or properties (MFSA 2012-83) (CVE-2012-3993, CVE-2012-4184)

- Mozilla: top object and location property accessible by plugins (MFSA 2012-82) (CVE-2012-3994)

- Mozilla: Use-after-free, buffer overflow, and out of bounds read issues found using Address Sanitizer (MFSA 2012-85) (CVE-2012-3995, CVE-2012-4179, CVE-2012-4180, CVE-2012-4181, CVE-2012-4182, CVE-2012-4183)

- Mozilla: Heap memory corruption issues found using Address Sanitizer (MFSA 2012-86) (CVE-2012-4185, CVE-2012-4186, CVE-2012-4187, CVE-2012-4188)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL thunderbird package based on the guidance in RHSA-2012:1351.

See Also

http://www.nessus.org/u?146e3214

https://access.redhat.com/errata/RHSA-2012:1351

https://access.redhat.com/security/updates/classification/#critical

https://bugzilla.redhat.com/show_bug.cgi?id=851912

https://bugzilla.redhat.com/show_bug.cgi?id=863614

https://bugzilla.redhat.com/show_bug.cgi?id=863618

https://bugzilla.redhat.com/show_bug.cgi?id=863619

https://bugzilla.redhat.com/show_bug.cgi?id=863621

https://bugzilla.redhat.com/show_bug.cgi?id=863622

https://bugzilla.redhat.com/show_bug.cgi?id=863623

https://bugzilla.redhat.com/show_bug.cgi?id=863624

https://bugzilla.redhat.com/show_bug.cgi?id=863625

https://bugzilla.redhat.com/show_bug.cgi?id=863626

https://bugzilla.redhat.com/show_bug.cgi?id=863628

Plugin Details

Severity: Medium

ID: 62473

File Name: redhat-RHSA-2012-1351.nasl

Version: 1.34

Type: local

Agent: unix

Published: 10/10/2012

Updated: 4/27/2024

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2012-4188

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS Score Source: CVE-2012-3994

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:thunderbird, cpe:/o:redhat:enterprise_linux:5, cpe:/o:redhat:enterprise_linux:6

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/9/2012

Vulnerability Publication Date: 8/29/2012

Exploitable With

Metasploit (Firefox 5.0 - 15.0.1 __exposedProps__ XCS Code Execution)

Reference Information

CVE: CVE-2012-1956, CVE-2012-3982, CVE-2012-3986, CVE-2012-3988, CVE-2012-3990, CVE-2012-3991, CVE-2012-3992, CVE-2012-3993, CVE-2012-3994, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180, CVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4184, CVE-2012-4185, CVE-2012-4186, CVE-2012-4187, CVE-2012-4188

BID: 55260

CWE: 125, 416

RHSA: 2012:1351