-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2008-9859 2008-11-21 09:21:43 --------------------------------------------------------------------------------
Name : thunderbird Product : Fedora 9 Version : 2.0.0.18 Release : 1.fc9 URL : http://www.mozilla.org/projects/thunderbird/ Summary : Mozilla Thunderbird mail/newsgroup client Description : Mozilla Thunderbird is a standalone mail and newsgroup client. -------------------------------------------------------------------------------- Update Information: This update update upgrades thunderbird packages to upstream version 2.0.0.18, which fixes multiple security issues detailed in upstream security advisories: http://www.mozilla.org/security/known- vulnerabilities/thunderbird20.html#thunderbird2.0.0.17 http://www.mozilla.org/security/known- vulnerabilities/thunderbird20.html#thunderbird2.0.0.18 -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 19 2008 Christopher Aillon <[EMAIL PROTECTED]> 2.0.0.18-1 - Update to 2.0.0.18 * Thu Oct 9 2008 Christopher Aillon <[EMAIL PROTECTED]> 2.0.0.17-1 - Update to 2.0.0.17 * Wed Jul 23 2008 Christopher Aillon <[EMAIL PROTECTED]> 2.0.0.16-1 - Update to 2.0.0.16 -------------------------------------------------------------------------------- References: [ 1 ] Bug #470864 - CVE-2008-5012 Mozilla Image stealing via canvas and HTTP redirect https://bugzilla.redhat.com/show_bug.cgi?id=470864 [ 2 ] Bug #470881 - CVE-2008-5016 Mozilla crash with evidence of memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=470881 [ 3 ] Bug #470894 - CVE-2008-5021 Mozilla crash and remote code execution in nsFrameManager https://bugzilla.redhat.com/show_bug.cgi?id=470894 [ 4 ] Bug #470902 - CVE-2008-5024 Mozilla parsing error in E4X default namespace https://bugzilla.redhat.com/show_bug.cgi?id=470902 [ 5 ] Bug #463181 - CVE-2008-0016 Mozilla UTF-8 stack buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=463181 [ 6 ] Bug #463182 - CVE-2008-3835 mozilla: nsXMLDocument::OnChannelRedirect() same-origin violation https://bugzilla.redhat.com/show_bug.cgi?id=463182 [ 7 ] Bug #463190 - CVE-2008-4058 Mozilla privilege escalation via XPCnativeWrapper pollution https://bugzilla.redhat.com/show_bug.cgi?id=463190 [ 8 ] Bug #463192 - CVE-2008-4059 Mozilla privilege escalation via XPCnativeWrapper pollution https://bugzilla.redhat.com/show_bug.cgi?id=463192 [ 9 ] Bug #463198 - CVE-2008-4060 Mozilla privilege escalation via XPCnativeWrapper pollution https://bugzilla.redhat.com/show_bug.cgi?id=463198 [ 10 ] Bug #463199 - CVE-2008-4061 Mozilla layout engine crash https://bugzilla.redhat.com/show_bug.cgi?id=463199 [ 11 ] Bug #463201 - CVE-2008-4062 Mozilla crashes with evidence of memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=463201 [ 12 ] Bug #463234 - CVE-2008-4065 Mozilla BOM characters stripped from JavaScript before execution https://bugzilla.redhat.com/show_bug.cgi?id=463234 [ 13 ] Bug #463243 - CVE-2008-4066 Mozilla low surrogates stripped from JavaScript before execution https://bugzilla.redhat.com/show_bug.cgi?id=463243 [ 14 ] Bug #463246 - CVE-2008-4067 Mozilla resource: traversal vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=463246 [ 15 ] Bug #463248 - CVE-2008-4068 Mozilla local HTML file recource: bypass https://bugzilla.redhat.com/show_bug.cgi?id=463248 [ 16 ] Bug #464041 - CVE-2008-4070 Thunderbird cancelled newsgrop messages https://bugzilla.redhat.com/show_bug.cgi?id=464041 [ 17 ] Bug #470873 - CVE-2008-5014 Mozilla crash and remote code execution via __proto__ tampering https://bugzilla.redhat.com/show_bug.cgi?id=470873 [ 18 ] Bug #470883 - CVE-2008-5017 Mozilla crash with evidence of memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=470883 [ 19 ] Bug #470884 - CVE-2008-5018 Mozilla crash with evidence of memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=470884 [ 20 ] Bug #470895 - CVE-2008-5022 Mozilla nsXMLHttpRequest::NotifyEventListeners() same-origin violation https://bugzilla.redhat.com/show_bug.cgi?id=470895 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update thunderbird' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-announce