[SECURITY] Fedora 8 Update: thunderbird-2.0.0.18-1.fc8
updates at fedoraproject.org
updates at fedoraproject.org
Fri Nov 21 10:57:04 UTC 2008
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-9807
2008-11-21 09:13:23
--------------------------------------------------------------------------------
Name : thunderbird
Product : Fedora 8
Version : 2.0.0.18
Release : 1.fc8
URL : http://www.mozilla.org/projects/thunderbird/
Summary : Mozilla Thunderbird mail/newsgroup client
Description :
Mozilla Thunderbird is a standalone mail and newsgroup client.
--------------------------------------------------------------------------------
Update Information:
This update update upgrades thunderbird packages to upstream version 2.0.0.18,
which fixes multiple security issues detailed in upstream security advisories:
http://www.mozilla.org/security/known-
vulnerabilities/thunderbird20.html#thunderbird2.0.0.17
http://www.mozilla.org/security/known-
vulnerabilities/thunderbird20.html#thunderbird2.0.0.18
--------------------------------------------------------------------------------
ChangeLog:
* Wed Nov 19 2008 Christopher Aillon <caillon at redhat.com> 2.0.0.18-1
- Update to 2.0.0.18
* Thu Oct 9 2008 Christopher Aillon <caillon at redhat.com> 2.0.0.17-1
- Update to 2.0.0.17
* Wed Jul 23 2008 Christopher Aillon <caillon at redhat.com> 2.0.0.16-1
- Update to 2.0.0.16
* Thu May 1 2008 Christopher Aillon <caillon at redhat.com> 2.0.0.14-1
- Update to 2.0.0.14
* Fri Mar 7 2008 Martin Stransky <stransky at redhat.com>
- updated starting script, fixes #436410
* Tue Feb 26 2008 Christopher Aillon <caillon at redhat.com> 2.0.0.12-1
- Update to 2.0.0.12
* Thu Nov 15 2007 Christopher Aillon <caillon at redhat.com> 2.0.0.9-1
- Update to 2.0.0.9
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #463181 - CVE-2008-0016 Mozilla UTF-8 stack buffer overflow
https://bugzilla.redhat.com/show_bug.cgi?id=463181
[ 2 ] Bug #463190 - CVE-2008-4058 Mozilla privilege escalation via XPCnativeWrapper pollution
https://bugzilla.redhat.com/show_bug.cgi?id=463190
[ 3 ] Bug #463198 - CVE-2008-4060 Mozilla privilege escalation via XPCnativeWrapper pollution
https://bugzilla.redhat.com/show_bug.cgi?id=463198
[ 4 ] Bug #463201 - CVE-2008-4062 Mozilla crashes with evidence of memory corruption
https://bugzilla.redhat.com/show_bug.cgi?id=463201
[ 5 ] Bug #463182 - CVE-2008-3835 mozilla: nsXMLDocument::OnChannelRedirect() same-origin violation
https://bugzilla.redhat.com/show_bug.cgi?id=463182
[ 6 ] Bug #463192 - CVE-2008-4059 Mozilla privilege escalation via XPCnativeWrapper pollution
https://bugzilla.redhat.com/show_bug.cgi?id=463192
[ 7 ] Bug #463199 - CVE-2008-4061 Mozilla layout engine crash
https://bugzilla.redhat.com/show_bug.cgi?id=463199
[ 8 ] Bug #463234 - CVE-2008-4065 Mozilla BOM characters stripped from JavaScript before execution
https://bugzilla.redhat.com/show_bug.cgi?id=463234
[ 9 ] Bug #463246 - CVE-2008-4067 Mozilla resource: traversal vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=463246
[ 10 ] Bug #464041 - CVE-2008-4070 Thunderbird cancelled newsgrop messages
https://bugzilla.redhat.com/show_bug.cgi?id=464041
[ 11 ] Bug #470873 - CVE-2008-5014 Mozilla crash and remote code execution via __proto__ tampering
https://bugzilla.redhat.com/show_bug.cgi?id=470873
[ 12 ] Bug #470883 - CVE-2008-5017 Mozilla crash with evidence of memory corruption
https://bugzilla.redhat.com/show_bug.cgi?id=470883
[ 13 ] Bug #470894 - CVE-2008-5021 Mozilla crash and remote code execution in nsFrameManager
https://bugzilla.redhat.com/show_bug.cgi?id=470894
[ 14 ] Bug #470902 - CVE-2008-5024 Mozilla parsing error in E4X default namespace
https://bugzilla.redhat.com/show_bug.cgi?id=470902
[ 15 ] Bug #463243 - CVE-2008-4066 Mozilla low surrogates stripped from JavaScript before execution
https://bugzilla.redhat.com/show_bug.cgi?id=463243
[ 16 ] Bug #463248 - CVE-2008-4068 Mozilla local HTML file recource: bypass
https://bugzilla.redhat.com/show_bug.cgi?id=463248
[ 17 ] Bug #470864 - CVE-2008-5012 Mozilla Image stealing via canvas and HTTP redirect
https://bugzilla.redhat.com/show_bug.cgi?id=470864
[ 18 ] Bug #470881 - CVE-2008-5016 Mozilla crash with evidence of memory corruption
https://bugzilla.redhat.com/show_bug.cgi?id=470881
[ 19 ] Bug #470884 - CVE-2008-5018 Mozilla crash with evidence of memory corruption
https://bugzilla.redhat.com/show_bug.cgi?id=470884
[ 20 ] Bug #470895 - CVE-2008-5022 Mozilla nsXMLHttpRequest::NotifyEventListeners() same-origin violation
https://bugzilla.redhat.com/show_bug.cgi?id=470895
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update thunderbird' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
More information about the package-announce
mailing list