Ubuntu Security Notice USN-329-1
29th July, 2006
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 6.06 LTS
Various flaws have been reported that allow an attacker to execute
arbitrary code with user privileges by tricking the user into opening
is disabled by default for emails, and it is not recommended to enable
it. (CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3805,
CVE-2006-3806, CVE-2006-3807, CVE-2006-3809, CVE-2006-3810,
A buffer overflow has been discovered in the handling of .vcard files.
By tricking a user into importing a malicious vcard into his contacts,
this could be exploited to execute arbitrary code with the user's
The "enigmail" plugin has been updated to work with the new
The problem can be corrected by updating your system to the following package version:
- Ubuntu 6.06 LTS:
- mozilla-thunderbird 22.214.171.124-0ubuntu0.6.06
- mozilla-thunderbird-enigmail 2:0.94-0ubuntu4.2
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
After a standard system upgrade you need to restart Thunderbird to
effect the necessary changes.
Please note that Thunderbird 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are
also affected by these problems. Updates for these Ubuntu releases
will be delayed due to upstream dropping support for this Thunderbird
attack vectors for most vulnerabilities if you use one of these Ubuntu