[SECURITY] Fedora Core 5 Update: thunderbird-1.5.0.8-1.fc5

Christopher Aillon caillon at redhat.com
Wed Nov 8 13:02:57 UTC 2006


---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2006-1194
2006-11-08
---------------------------------------------------------------------

Product     : Fedora Core 5
Name        : thunderbird
Version     : 1.5.0.8
Release     : 1.fc5
Summary     : Mozilla Thunderbird mail/newsgroup client
Description :
Mozilla Thunderbird is a standalone mail and newsgroup client.

---------------------------------------------------------------------
Update Information:

Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way Thunderbird processes
certain malformed Javascript code. A malicious HTML mail
message could cause the execution of Javascript code in such
a way that could cause Thunderbird to crash or execute
arbitrary code as the user running Thunderbird.
(CVE-2006-5463, CVE-2006-5747, CVE-2006-5748)

Several flaws were found in the way Thunderbird renders HTML
mail messages. A malicious HTML mail message could cause the
mail client to crash or possibly execute arbitrary code as
the user running Thunderbird. (CVE-2006-5464)

Users of Thunderbird are advised to upgrade to this update,
which contains Thunderbird version 1.5.0.8 that corrects
these issues.

---------------------------------------------------------------------
* Tue Nov  7 2006 Christopher Aillon <caillon at redhat.com> 1.5.0.8-1
- Update to 1.5.0.8
- Allow choosing of download directory
- Take the user to the correct directory from the Download Manager.
- Patch to add support for printing via pango from Behdad.
- Sync up default invisible character with GTK+
* Wed Sep 13 2006 Christopher Aillon <caillon at redhat.com> - 1.5.0.7-1
- Update to 1.5.0.7
* Tue Aug  8 2006 Kai Engert <kengert at redhat.com> - 1.5.0.5-1.1
- Update to 1.5.0.5
- Use dist tag
* Mon Jun 12 2006 Kai Engert <kengert at redhat.com> - 1.5.0.4-1.1.fc5
- Update to 1.5.0.4
- Fix desktop-file-utils requires

---------------------------------------------------------------------
This update can be downloaded from:
    http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

f9a1980078e7ae391d679c32a2135ec242476498  SRPMS/thunderbird-1.5.0.8-1.fc5.src.rpm
f9a1980078e7ae391d679c32a2135ec242476498  noarch/thunderbird-1.5.0.8-1.fc5.src.rpm
17ba711eb6da49e8d30a3455160c4f1d2cf97cc0  ppc/debug/thunderbird-debuginfo-1.5.0.8-1.fc5.ppc.rpm
796694e20da80b473192e4f44a92149e4d9e2f27  ppc/thunderbird-1.5.0.8-1.fc5.ppc.rpm
cea6166201546bc63c3d9803f29ce595ab89257a  x86_64/debug/thunderbird-debuginfo-1.5.0.8-1.fc5.x86_64.rpm
9fa6c7b48a004be10dbe3feebf0dbc473a4b6399  x86_64/thunderbird-1.5.0.8-1.fc5.x86_64.rpm
0276bb779a4fcdee5557e9e82d861e805f039065  i386/thunderbird-1.5.0.8-1.fc5.i386.rpm
5e8e4c41f1fff96e26e857848bfa97e542541f6f  i386/debug/thunderbird-debuginfo-1.5.0.8-1.fc5.i386.rpm

This update can be installed with the 'yum' update program.  Use 'yum update
package-name' at the command line.  For more information, refer to 'Managing
Software with yum,' available at http://fedora.redhat.com/docs/yum/.
---------------------------------------------------------------------




More information about the package-announce mailing list