Debian Security Advisory
DSA-3601-1 icedove -- security update
- Date Reported:
- 13 Jun 2016
- Affected Packages:
- icedove
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2016-2806.
- More information:
-
Multiple security issues have been found in Icedove, Debian's version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service.
Debian follows the extended support releases (ESR) of Thunderbird. Support for the 38.x series has ended, so starting with this update we're now following the 45.x releases.
For the stable distribution (jessie), this problem has been fixed in version 1:45.1.0-1~deb8u1.
For the testing distribution (stretch), this problem has been fixed in version 1:45.1.0-1.
For the unstable distribution (sid), this problem has been fixed in version 1:45.1.0-1.
We recommend that you upgrade your icedove packages.