Debian Security Advisory
DSA-3324-1 icedove -- security update
- Date Reported:
- 01 Aug 2015
- Affected Packages:
- icedove
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2015-2721, CVE-2015-2724, CVE-2015-2734, CVE-2015-2735, CVE-2015-2736, CVE-2015-2737, CVE-2015-2738, CVE-2015-2739, CVE-2015-2740, CVE-2015-4000.
- More information:
-
Multiple security issues have been found in Icedove, Debian's version of the Mozilla Thunderbird mail client: multiple memory safety errors, use-after-frees and other implementation errors may lead to the execution of arbitrary code or denial of service. This update also addresses a vulnerability in DHE key processing commonly known as the
LogJam
vulnerability.For the oldstable distribution (wheezy), these problems have been fixed in version 31.8.0-1~deb7u1.
For the stable distribution (jessie), these problems have been fixed in version 31.8.0-1~deb8u1.
For the unstable distribution (sid), these problems will be fixed shortly.
We recommend that you upgrade your icedove packages.