MozillaThunderbird: The standalone Mozilla Mail component. ---------------------------------------------------------------------- Datei: MozillaThunderbird-1.0.8-0.1.i586.rpm Patchrpm: MozillaThunderbird-1.0.8-0.1.i586.patch.rpm Version: 1.0.8-0.1 Größe: 10064 kB Patchgröße: 9753 kB Datum: Mit 12 Apr 2006 15:36:22 CEST Source: MozillaThunderbird-1.0.8-0.1.src.rpm Security: Ja ---------------------------------------------------------------------- Beschreibung: Dieses Update behebt mehrere Sicherheitsprobleme im Mozilla Thunderbird Mailprogramm, und bringt Thunderbird auf Version 1.0.8. Detailierte List der Probleme (english): Fixed in Thunderbird 1.0.8 (SUSE Linux 9.1, 9.2, 9.3 and 10.0) MFSA 2006-27/CVE-2006-0748 - Table Rebuilding Code Execution Vulnerability MFSA 2006-26/CVE-2006-1045 - Mail Multiple Information Disclosure MFSA 2006-25/CVE-2006-1727 - Privilege escalation through Print Preview MFSA 2006-24/CVE-2006-1728 - Privilege escalation using crypto.generateCRMFRequest MFSA 2006-22/CVE-2006-1730 - CSS Letter-Spacing Heap Overflow Vulnerability MFSA 2006-21/CVE-2006-0884 - JavaScript execution in mail when forwarding in-line MFSA 2006-19/CVE-2006-1731 - Cross-site scripting using .valueOf.call() MFSA 2006-18/CVE-2006-0749 - Mozilla Firefox Tag Order Vulnerability MFSA 2006-17/CVE-2006-1732 - cross-site scripting through window.controllers MFSA 2006-16/CVE-2006-1733 - Accessing XBL compilation scope via valueOf.call() MFSA 2006-15/CVE-2006-1734 - Privilege escalation using a JavaScript function's cloned parent MFSA 2006-14/CVE-2006-1735 - Privilege escalation via XBL.method.eval MFSA 2006-11/CVE-2006-1737/CVE-2006-1739 - Crashes with evidence of memory corruption (rv:1.8) MFSA 2006-10/CVE-2006-1742 - JavaScript garbage-collection hazard audit MFSA 2006-09/CVE-2006-1741 - Cross-site JavaScript injection using event handlers MFSA 2006-05/CVE-2006-0296 - Localstore.rdf XML injection through XULDocument.persist() MFSA 2006-01/CVE-2006-0292 - JavaScript garbage-collection hazards Fixed in Thunderbird 1.0.7 (SUSE Linux 9.1, 9.2, 9.3 and 10.0) MFSA 2005-59/CVE-2005-2707 - Command-line handling on Linux allows shell execution MFSA 2005-58/CVE-2005-2706 - Firefox 1.0.7 / Mozilla Suite 1.7.12 Vulnerability Fixes Fixed in Thunderbird 1.0.5/1.0.6 (SUSE Linux 9.1, 9.2 and 9.3) MFSA 2005-56/CVE-2005-2270 - Code execution through shared function objects MFSA 2005-55/CVE-2005-2269 - XHTML node spoofing MFSA 2005-52/CVE-2005-2266 - Same origin violation: frame calling top.focus() MFSA 2005-50/CVE-2005-2265 - Exploitable crash in InstallVersion.compareTo() MFSA 2005-46/CVE-2005-2261 - XBL scripts ran even when Javascript disabled MFSA 2005-44/CVE-2005-1532 - Privilege escalation via non-DOM property overrides MFSA 2005-41/CVE-2005-1160 - Privilege escalation via DOM property overrides MFSA 2005-40/CVE-2005-1159 - Missing Install object instance checks MFSA 2005-33/CVE-2005-0989 - Javascript "lambda" replace exposes memory contents Fixed in Thunderbird 1.0.2 (SUSE Linux 9.1, 9.2 and 9.3) MFSA 2005-30/CVE-2005-0399 - GIF heap overflow parsing Netscape extension 2 MFSA 2005-25/CVE-2005-0230 - Image drag and drop executable spoofing MFSA 2005-21/CVE-2005-0587 - Overwrite arbitrary files downloading .lnk twice MFSA 2005-18/CVE-2005-0255 - Memory overwrite in string library MFSA 2005-17/CVE-2005-0590 - Install source spoofing with user:pass@host MFSA 2005-15/CVE-2005-0592 - Heap overflow possible in UTF8 to Unicode conversion Fixed in Thunderbird 1.0 (SUSE Linux 9.1 and 9.2) MFSA 2005-11/CVE-2005-0149 - Mail client responds to cookie requests Fixed in Thunderbird 0.9 (SUSE Linux 9.1 and 9.2) MFSA 2005-06/CVE-2004-1316 - Heap overrun handling malicious news: URL MFSA 2005-02/CVE-2005-0142 - Opened attachments are temporarily saved world-readable