{"id":"USN-2373-1","summary":"thunderbird vulnerabilities","details":"Bobby Holley, Christian Holler, David Bolter, Byron Campen and Jon\nCoppeard discovered multiple memory safety issues in Thunderbird. If a\nuser were tricked in to opening a specially crafted message with scripting\nenabled, an attacker could potentially exploit these to cause a denial of\nservice via application crash, or execute arbitrary code with the\nprivileges of the user invoking Thunderbird. (CVE-2014-1574)\n\nAtte Kettunen discovered a buffer overflow during CSS manipulation. If a\nuser were tricked in to opening a specially crafted message, an attacker\ncould potentially exploit this to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Thunderbird. (CVE-2014-1576)\n\nHolger Fuhrmannek discovered an out-of-bounds read with Web Audio. If a\nuser were tricked in to opening a specially crafted message with scripting\nenabled, an attacker could potentially exploit this to steal sensitive\ninformation. (CVE-2014-1577)\n\nAbhishek Arya discovered an out-of-bounds write when buffering WebM video\nin some circumstances. If a user were tricked in to opening a specially\ncrafted message with scripting enabled, an attacker could potentially\nexploit this to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2014-1578)\n\nA use-after-free was discovered during text layout in some circumstances.\nIf a user were tricked in to opening a specially crafted message with\nscripting enabled, an attacker could potentially exploit this to cause a\ndenial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2014-1581)\n\nEric Shepherd and Jan-Ivar Bruaroey discovered issues with video sharing\nvia WebRTC in iframes, where video continues to be shared after being\nstopped and navigating to a new site doesn't turn off the camera. An\nattacker could potentially exploit this to access the camera without the\nuser being aware. (CVE-2014-1585, CVE-2014-1586)\n","modified":"2026-04-22T09:03:51.482162Z","published":"2014-10-15T14:27:40Z","related":["UBUNTU-CVE-2014-1574","UBUNTU-CVE-2014-1576","UBUNTU-CVE-2014-1577","UBUNTU-CVE-2014-1578","UBUNTU-CVE-2014-1581","UBUNTU-CVE-2014-1585","UBUNTU-CVE-2014-1586"],"upstream":["CVE-2014-1574","CVE-2014-1576","CVE-2014-1577","CVE-2014-1578","CVE-2014-1581","CVE-2014-1585","CVE-2014-1586","UBUNTU-CVE-2014-1574","UBUNTU-CVE-2014-1576","UBUNTU-CVE-2014-1577","UBUNTU-CVE-2014-1578","UBUNTU-CVE-2014-1581","UBUNTU-CVE-2014-1585","UBUNTU-CVE-2014-1586"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-2373-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-1574"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-1576"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-1577"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-1578"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-1581"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-1585"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-1586"}],"affected":[{"package":{"name":"thunderbird","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/thunderbird@1:31.2.0+build2-0ubuntu0.14.04.1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:31.2.0+build2-0ubuntu0.14.04.1"}]}],"versions":["1:24.0+build1-0ubuntu1","1:24.0+build1-0ubuntu2","1:24.1.1+build1-0ubuntu0.13.10.1","1:24.1.1+build1-0ubuntu1","1:24.2.0+build1-0ubuntu1","1:24.4.0+build1-0ubuntu1","1:24.5.0+build1-0ubuntu0.14.04.1","1:24.6.0+build1-0ubuntu0.14.04.1","1:31.0+build1-0ubuntu0.14.04.1","1:31.1.1+build1-0ubuntu0.14.04.1","1:31.1.2+build1-0ubuntu0.14.04.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"thunderbird","binary_version":"1:31.2.0+build2-0ubuntu0.14.04.1"},{"binary_name":"thunderbird-globalmenu","binary_version":"1:31.2.0+build2-0ubuntu0.14.04.1"},{"binary_name":"thunderbird-gnome-support","binary_version":"1:31.2.0+build2-0ubuntu0.14.04.1"},{"binary_name":"thunderbird-mozsymbols","binary_version":"1:31.2.0+build2-0ubuntu0.14.04.1"},{"binary_name":"thunderbird-testsuite","binary_version":"1:31.2.0+build2-0ubuntu0.14.04.1"},{"binary_name":"xul-ext-calendar-timezones","binary_version":"1:31.2.0+build2-0ubuntu0.14.04.1"},{"binary_name":"xul-ext-gdata-provider","binary_version":"1:31.2.0+build2-0ubuntu0.14.04.1"},{"binary_name":"xul-ext-lightning","binary_version":"1:31.2.0+build2-0ubuntu0.14.04.1"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2014-1574","severity":[{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2014-1576","severity":[{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2014-1577","severity":[{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2014-1578","severity":[{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2014-1581","severity":[{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2014-1585","severity":[{"score":"low","type":"Ubuntu"}]},{"id":"CVE-2014-1586","severity":[{"score":"low","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:14.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2373-1.json"}}],"schema_version":"1.7.5"}