Fixed at least in Xenial:

$ hardening-check /usr/lib/thunderbird/thunderbird
/usr/lib/thunderbird/thunderbird:
 Position Independent Executable: yes
 Stack protected: yes
 Fortify Source functions: yes (some protected functions found)
 Read-only relocations: yes
 Immediate binding: yes


$ apt-cache policy thunderbird
thunderbird:
  Installed: 1:52.2.1+build1-0ubuntu0.16.04.1
  Candidate: 1:52.2.1+build1-0ubuntu0.16.04.1
  Version table:
 *** 1:52.2.1+build1-0ubuntu0.16.04.1 500
        500 http://archive.ubuntu.com/ubuntu xenial-updates/main amd64 Packages
        500 http://security.ubuntu.com/ubuntu xenial-security/main amd64 
Packages
        100 /var/lib/dpkg/status
     1:38.6.0+build1-0ubuntu1 500
        500 http://archive.ubuntu.com/ubuntu xenial/main amd64 Packages

$ lsb_release -rd
Description:    Ubuntu 16.04.3 LTS
Release:        16.04


** Changed in: thunderbird (Ubuntu)
       Status: New => Fix Released

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to thunderbird in Ubuntu.
https://bugs.launchpad.net/bugs/1185971

Title:
  Please enable all hardening features

Status in thunderbird package in Ubuntu:
  Fix Released

Bug description:
  Thunderbird now integrates a built-in browser as well as IM
  capabilities. As such, it should be built with hardening features
  enabled as it's the case for both Firefox and Pidgin.

  Thunderbird (missing PIE and BIND_NOW):
  $ hardening-check /usr/lib/thunderbird/thunderbird
  /usr/lib/thunderbird/thunderbird:
    Position Independent Executable: no, normal executable!
    Stack protected: yes
    Fortify Source functions: yes (some protected functions found)
    Read-only relocations: yes
    Immediate binding: no not found!

  Firefox:
  $ hardening-check /usr/lib/firefox/firefox
  /usr/lib/firefox/firefox:
   Position Independent Executable: yes
   Stack protected: yes
   Fortify Source functions: yes (some protected functions found)
   Read-only relocations: yes
   Immediate binding: yes

  Pidgin:
  $ hardening-check /usr/bin/pidgin 
  /usr/bin/pidgin:
   Position Independent Executable: yes
   Stack protected: yes
   Fortify Source functions: yes (some protected functions found)
   Read-only relocations: yes
   Immediate binding: yes

  
  Additional informations:

  $ lsb_release -rd
  Description:  Ubuntu 12.04.2 LTS
  Release:      12.04

  $ apt-cache policy thunderbird
  thunderbird:
    Installed: 17.0.6+build1-0ubuntu0.12.04.1
    Candidate: 17.0.6+build1-0ubuntu0.12.04.1
    Version table:
   *** 17.0.6+build1-0ubuntu0.12.04.1 0
          500 http://archive.ubuntu.com/ubuntu/ precise-updates/main amd64 
Packages
          500 http://security.ubuntu.com/ubuntu/ precise-security/main amd64 
Packages
          100 /var/lib/dpkg/status
       11.0.1+build1-0ubuntu2 0
          500 http://archive.ubuntu.com/ubuntu/ precise/main amd64 Packages

  ProblemType: Bug
  DistroRelease: Ubuntu 12.04
  Package: thunderbird 17.0.6+build1-0ubuntu0.12.04.1
  ProcVersionSignature: Ubuntu 3.2.0-44.69-generic 3.2.44
  Uname: Linux 3.2.0-44-generic x86_64
  AddonCompatCheckDisabled: False
  AlsaVersion: Advanced Linux Sound Architecture Driver Version 1.0.24.
  ApportVersion: 2.0.1-0ubuntu17.2
  Architecture: amd64
  ArecordDevices:
   **** List of CAPTURE Hardware Devices ****
   card 0: Intel [HDA Intel], device 0: CONEXANT Analog [CONEXANT Analog]
     Subdevices: 1/1
     Subdevice #0: subdevice #0
  AudioDevicesInUse:
   USER        PID ACCESS COMMAND
   /dev/snd/controlC0:  simon      4033 F.... pulseaudio
  BuildID: 20130510125938
  CRDA: Error: [Errno 2] No such file or directory
  Card0.Amixer.info:
   Card hw:0 'Intel'/'HDA Intel at 0xf2620000 irq 44'
     Mixer name : 'Intel IbexPeak HDMI'
     Components : 'HDA:14f15069,17aa214c,00100302 
HDA:80862804,17aa21b5,00100000'
     Controls      : 26
     Simple ctrls  : 8
  Card29.Amixer.info:
   Card hw:29 'ThinkPadEC'/'ThinkPad Console Audio Control at EC reg 0x30, fw 
6IHT43WW-1.18'
     Mixer name : 'ThinkPad EC 6IHT43WW-1.18'
     Components : ''
     Controls      : 1
     Simple ctrls  : 1
  Card29.Amixer.values:
   Simple mixer control 'Console',0
     Capabilities: pswitch pswitch-joined penum
     Playback channels: Mono
     Mono: Playback [on]
  Channel: Unavailable
  CurrentDmesg: dmesg: klogctl failed: Operation not permitted
  Date: Thu May 30 15:03:52 2013
  ForcedLayersAccel: False
  MarkForUpload: True
  MostRecentCrashID: bp-fb66e348-31a9-40cf-b705-211802130411
  Plugins: Shockwave Flash - /usr/lib/adobe-flashplugin/libflashplayer.so 
(adobe-flashplugin)
  ProcEnviron:
   LANGUAGE=en_CA:en
   TERM=xterm
   PATH=(custom, no user)
   LANG=en_CA.UTF-8
   SHELL=/bin/bash
  Profiles: Profile0 (Default) - LastVersion=17.0.6/20130510125938 (In use)
  RelatedPackageVersions: adobe-flashplugin 11.2.202.285-0precise1
  RfKill:
   0: phy0: Wireless LAN
        Soft blocked: no
        Hard blocked: no
  RunningIncompatibleAddons: False
  SourcePackage: thunderbird
  UpgradeStatus: No upgrade log present (probably fresh install)
  dmi.bios.date: 09/26/2012
  dmi.bios.vendor: LENOVO
  dmi.bios.version: 6IET84WW (1.44 )
  dmi.board.name: 2516CTO
  dmi.board.vendor: LENOVO
  dmi.board.version: Not Available
  dmi.chassis.asset.tag: No Asset Information
  dmi.chassis.type: 10
  dmi.chassis.vendor: LENOVO
  dmi.chassis.version: Not Available
  dmi.modalias: 
dmi:bvnLENOVO:bvr6IET84WW(1.44):bd09/26/2012:svnLENOVO:pn2516CTO:pvrThinkPadT410:rvnLENOVO:rn2516CTO:rvrNotAvailable:cvnLENOVO:ct10:cvrNotAvailable:
  dmi.product.name: 2516CTO
  dmi.product.version: ThinkPad T410
  dmi.sys.vendor: LENOVO

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1185971/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : [email protected]
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to