Gentoo Archives: gentoo-announce

From: Matthias Geerdsen <vorlon@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200610-01 ] Mozilla Thunderbird: Multiple vulnerabilities
Date: Wed, 04 Oct 2006 19:37:40
Message-Id: 4524081A.4070000@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200610-01
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Mozilla Thunderbird: Multiple vulnerabilities
9 Date: October 04, 2006
10 Bugs: #147653
11 ID: 200610-01
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 The Mozilla Foundation has reported multiple security vulnerabilities
19 related to Mozilla Thunderbird.
20
21 Background
22 ==========
23
24 The Mozilla Thunderbird mail client is a redesign of the Mozilla Mail
25 component.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 mozilla-thunderbird < 1.5.0.7 >= 1.5.0.7
34 2 mozilla-thunderbird-bin < 1.5.0.7 >= 1.5.0.7
35 -------------------------------------------------------------------
36 2 affected packages on all of their supported architectures.
37 -------------------------------------------------------------------
38
39 Description
40 ===========
41
42 A number of vulnerabilities have been found and fixed in Mozilla
43 Thunderbird. For details please consult the references below.
44
45 Impact
46 ======
47
48 The most severe vulnerabilities might lead to the execution of
49 arbitrary code with the rights of the user running the application.
50 Other vulnerabilities include program crashes and the acceptance of
51 forged certificates.
52
53 Workaround
54 ==========
55
56 There is no known workaround at this time.
57
58 Resolution
59 ==========
60
61 All Mozilla Thunderbird users should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot --verbose
65 ">=mail-client/mozilla-thunderbird-1.5.0.7"
66
67 All Mozilla Thunderbird binary users should upgrade to the latest
68 version:
69
70 # emerge --sync
71 # emerge --ask --oneshot --verbose
72 ">=mail-client/mozilla-thunderbird-bin-1.5.0.7"
73
74 References
75 ==========
76
77 [ 1 ] CVE-2006-4253
78 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4253
79 [ 2 ] CVE-2006-4340
80 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4340
81 [ 3 ] CVE-2006-4565
82 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4565
83 [ 4 ] CVE-2006-4566
84 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4566
85 [ 5 ] CVE-2006-4567
86 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4567
87 [ 6 ] CVE-2006-4570
88 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4570
89 [ 7 ] CVE-2006-4571
90 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4571
91
92 Availability
93 ============
94
95 This GLSA and any updates to it are available for viewing at
96 the Gentoo Security Website:
97
98 http://security.gentoo.org/glsa/glsa-200610-01.xml
99
100 Concerns?
101 =========
102
103 Security is a primary focus of Gentoo Linux and ensuring the
104 confidentiality and security of our users machines is of utmost
105 importance to us. Any security concerns should be addressed to
106 security@g.o or alternatively, you may file a bug at
107 http://bugs.gentoo.org.
108
109 License
110 =======
111
112 Copyright 2006 Gentoo Foundation, Inc; referenced text
113 belongs to its owner(s).
114
115 The contents of this document are licensed under the
116 Creative Commons - Attribution / Share Alike license.
117
118 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature