Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· OCZ Vertex 450 SSD Reviews and more
· Proxmox VE 3.0 released
· More Windows 8.1 features discovered in WinRT?
· New Colors Rumored for iPhone 5S and Lower-Cost iPhone, Dual LED Flash for iPhone 5S?
· NVIDIA GeForce 320.18 WHQL Drivers
· 20 Debian Updates
· OCZ Vertex 450 Series Solid State Drives announced
· NVIDIA GeForce GTX 780 Reviews Roundup
· Apple's 'iWatch' to come in late 2014 with focus on biometrics, analyst says
· Windows 8.1 laptops with AMDs new chips to support wireless display

Upcoming News
· A Futurelooks News Flash - An Affordable Titan – N?= VIDIA’s GEFORCE GTX 780 Reviewed
· News: AMD's A4-5000 'Kabini' APU reviewed
· Wine release 1.5.31
· NVIDIA GeForce Chips Comparison Table @ Hardware Secrets
· Resident Evil Revelations Video Review with Kaeyi Dream @ HardwareHeaven.com
· [security-announce] openSUSE-SU-2013:0825-1: important: MozillaFirefox: update to version 21.0
· [security-announce] SUSE-SU-2013:0819-2: critical: Security update for Linux kernel
· Fractal Design Node 605 Silent HTPC Case Review @ Legit Reviews
· SevenTeam X6 Power Bank Review (smartphones/tablets)
· Case Mod Friday: Smokey Green Giant @ ThinkComputers.org

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6498 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 711 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4599 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 786 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1173 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » September 2005 » [SECURITY] Fedora Core 3 Update: thunderbird-1.0.7-1.1.fc3

[SECURITY] Fedora Core 3 Update: thunderbird-1.0.7-1.1.fc3

Posted by Bob on: 09/30/2005 05:52 PM [ Print | 0 comment(s) ]

A new update is available for Fedora Core - [SECURITY] Fedora Core 3 Update: thunderbird-1.0.7-1.1.fc3. Here the announcement:




Fedora Update Notification
FEDORA-2005-962
2005-09-30
---------------------------------------------------------------------

Product : Fedora Core 3
Name : thunderbird
Version : 1.0.7
Release : 1.1.fc3
Summary : Mozilla Thunderbird mail/newsgroup client
Description :
Mozilla Thunderbird is a standalone mail and newsgroup client.

---------------------------------------------------------------------
Update Information:

An updated thunderbird package that fixes various bugs is
now available for Fedora Core 3.

This update has been rated as having important security
impact by the Fedora Security Response Team.

Mozilla Thunderbird is a standalone mail and newsgroup client.

A bug was found in the way Thunderbird processes certain
international domain names. An attacker could create a
specially crafted HTML file, which when viewed by the victim
would cause Thunderbird to crash or possibly execute
arbitrary code. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-2871
to this issue.

A bug was found in the way Thunderbird processes certain
Unicode sequences. It may be possible to execute arbitrary
code as the user running Thunderbird if the user views a
specially crafted Unicode sequence. (CAN-2005-2702)

A bug was found in the way Thunderbird makes XMLHttp
requests. It is possible that a malicious web page could
leverage this flaw to exploit other proxy or server flaws
from the victim's machine. It is also possible that this
flaw could be leveraged to send XMLHttp requests to hosts
other than the originator; the default behavior of the
browser is to disallow this. (CAN-2005-2703)

A bug was found in the way Thunderbird implemented its XBL
interface. It may be possible for a malicious web page to
create an XBL binding in such a way that would allow
arbitrary JavaScript execution with chrome permissions.
Please note that in Thunderbird 1.0.6 this issue is not
directly exploitable and will need to leverage other unknown
exploits. (CAN-2005-2704)

An integer overflow bug was found in Thunderbird's
JavaScript engine. Under favorable conditions, it may be
possible for a malicious mail message to execute arbitrary
code as the user running Thunderbird. Please note that
JavaScript support is disabled by default in Thunderbird.
(CAN-2005-2705)

A bug was found in the way Thunderbird displays about:
pages. It is possible for a malicious web page to open an
about: page, such as about:mozilla, in such a way that it
becomes possible to execute JavaScript with chrome
privileges. (CAN-2005-2706)

A bug was found in the way Thunderbird opens new windows. It
is possible for a malicious web site to construct a new
window without any user interface components, such as the
address bar and the status bar. This window could then be
used to mislead the user for malicious purposes. (CAN-2005-2707)

A bug was found in the way Thunderbird processes URLs passed
to it on the command line. If a user passes a malformed URL
to Thunderbird, such as clicking on a link in an instant
messaging program, it is possible to execute arbitrary
commands as the user running Thunderbird. (CAN-2005-2968)

Users of Thunderbird are advised to upgrade to this updated
package that contains Thunderbird version 1.0.7 and is not
vulnerable to these issues.
---------------------------------------------------------------------
* Thu Sep 29 2005 Christopher Aillon lt;caillon@redhat.comgt; 1.0.7-1.1.fc3
- Update to 1.0.7, containing fixes for:
CAN-2005-2701 CAN-2005-2702 CAN-2005-2703 CAN-2005-2704
CAN-2005-2705 CAN-2005-2706 CAN-2005-2707 CAN-2005-2968
CAN-2005-2871


---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

b7b046631b3da765dc140c9f63b3d363 SRPMS/thunderbird-1.0.7-1.1.fc3.src.rpm
d6510371fcd2c52eeaa63c209a12aa30 x86_64/thunderbird-1.0.7-1.1.fc3.x86_64.rpm
6da817d9b8ec25dfd4831b68deb22e87 x86_64/debug/thunderbird-debuginfo-1.0.7-1.1.fc3.x86_64.rpm
9ee12c4b9138486be4a97152eaa8738c i386/thunderbird-1.0.7-1.1.fc3.i386.rpm
0c8e1c1fcb44b43d838d98dce901f824 i386/debug/thunderbird-debuginfo-1.0.7-1.1.fc3.i386.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.


Bookmark and Share

« [SECURITY] Fedora Core 4 Update: thunderbird-1.0.7-1.1.fc4 · PhotoPlus 6 »

Linux Compatible » News » September 2005 » [SECURITY] Fedora Core 3 Update: thunderbird-1.0.7-1.1.fc3
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition