_______________________________________________________________________
Package : mozilla-thunderbird
Date : April 1, 2009
Affected: 2008.1, 2009.0, Corporate 3.0
_______________________________________________________________________
Problem Description:
A number of security vulnerabilities have been discovered in previous
versions, and corrected in the latest Mozilla Thunderbird program,
version 2.0.0.21 (CVE-2009-0040, CVE-2009-0776, CVE-2009-0771,
CVE-2009-0772, CVE-2009-0773, CVE-2009-0774, CVE-2009-0352,
CVE-2009-0353).
This update provides the latest Thunderbird to correct these issues.
Additionaly, Mozilla Thunderbird released with Mandriva Linux 2009.0,
when used with Enigmail extension on x86_64 architechture, would freeze
whenever any Enigmail function was used (bug #45001). Also, when used
on i586 architecture, Thunderbird would crash when sending an email,
if a file with an unknown extension was attached to it. (bug #46107)
This update also fixes those issues.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-0040
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-0352
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-0353
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-0771
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-0772
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-0773
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-0774
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-0776
http://www.mozilla.org/security/known-v ... rd2.0.0.21
https://qa.mandriva.com/45001
https://qa.mandriva.com/46107
_______________________________________________________________________