CVE-2010-0163

Publication date 18 March 2010

Last updated 24 July 2024


Ubuntu priority

Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted message, related to message indexing.

Status

Package Ubuntu Release Status
thunderbird 9.10 karmic
Fixed 2.0.0.24+build1+nobinonly-0ubuntu0.9.10.1
9.04 jaunty
Fixed 2.0.0.24+build1+nobinonly-0ubuntu0.9.04.1
8.10 intrepid
Fixed 2.0.0.24+build1+nobinonly-0ubuntu0.8.10.1
8.04 LTS hardy
Fixed 2.0.0.24+build1+nobinonly-0ubuntu0.8.04.1
6.06 LTS dapper Not in release

References

Related Ubuntu Security Notices (USN)

    • USN-915-1
    • Thunderbird vulnerabilities
    • 18 March 2010

Other references