MGASA-2013-0326

Source
https://advisories.mageia.org/MGASA-2013-0326.html
Import Source
https://advisories.mageia.org/MGASA-2013-0326.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2013-0326
Upstream
  • CVE-2013-5590
  • CVE-2013-5595
  • CVE-2013-5597
  • CVE-2013-5599
  • CVE-2013-5600
  • CVE-2013-5601
  • CVE-2013-5602
  • CVE-2013-5604
Published
2013-11-18T14:39:59Z
Modified
2026-04-16T06:25:05Z
Summary
Updated thunderbird package fixes security vulnerabilities
Details

Several flaws were found in the processing of malformed content. Malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird (CVE-2013-5590, CVE-2013-5597, CVE-2013-5599, CVE-2013-5600, CVE-2013-5601, CVE-2013-5602).

It was found that the Thunderbird JavaScript engine incorrectly allocated memory for certain functions. An attacker could combine this flaw with other vulnerabilities to execute arbitrary code with the privileges of the user running Thunderbird (CVE-2013-5595).

A flaw was found in the way Thunderbird handled certain Extensible Stylesheet Language Transformations (XSLT) files. An attacker could combine this flaw with other vulnerabilities to execute arbitrary code with the privileges of the user running Thunderbird (CVE-2013-5604).

Also, the thunderbird-lightning extension has been updated to a version that is compatible with the updated Thunderbird.

References
Credits

Affected packages

Mageia:2
thunderbird

Package

Name
thunderbird
Purl
pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
24.1.0-1.mga2

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0326.json"
thunderbird-l10n

Package

Name
thunderbird-l10n
Purl
pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
24.1.0-1.mga2

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0326.json"
thunderbird-lightning

Package

Name
thunderbird-lightning
Purl
pkg:rpm/mageia/thunderbird-lightning?arch=source&distro=mageia-2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.6.2-1.mga2

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0326.json"
Mageia:3
thunderbird

Package

Name
thunderbird
Purl
pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
24.1.0-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0326.json"
thunderbird-l10n

Package

Name
thunderbird-l10n
Purl
pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
24.1.0-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0326.json"
thunderbird-lightning

Package

Name
thunderbird-lightning
Purl
pkg:rpm/mageia/thunderbird-lightning?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.6.2-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0326.json"