MozillaThunderbirdMozillaThunderbird: Security update to 2.0.0.17MozillaThunderbird: Security update auf 2.0.0.17This update brings Mozilla Thunderbird to version 2.0.0.17.
It contains the following security fixes: MFSA 2008-46 /
CVE-2008-4070: Heap overflow when canceling a newsgroup
message
MFSA 2008-44 / CVE-2008-4067 / CVE-2008-4068: resource:
traversal vulnerabilities
MFSA 2008-43: BOM characters stripped from JavaScript
before execution CVE-2008-4065: Stripped BOM characters bug
CVE-2008-4066: HTML escaped low surrogates bug
MFSA 2008-42 Crashes with evidence of memory corruption
(rv:1.9.0.2/1.8.1.17): CVE-2008-4061: Jesse Ruderman
reported a crash in the layout engine. CVE-2008-4062: Igor
Bukanov, Philip Taylor, Georgi Guninski, and Antoine Labour
reported crashes in the JavaScript engine. CVE-2008-4063:
Jesse Ruderman, Bob Clary, and Martijn Wargers reported
crashes in the layout engine which only affected Firefox 3.
CVE-2008-4064: David Maciejak and Drew Yao reported crashes
in graphics rendering which only affected Firefox 3.
MFSA 2008-41 Privilege escalation via XPCnativeWrapper
pollution CVE-2008-4058: XPCnativeWrapper pollution bugs
CVE-2008-4059: XPCnativeWrapper pollution (Firefox 2)
CVE-2008-4060: Documents without script handling objects
MFSA 2008-38 / CVE-2008-3835:
nsXMLDocument::OnChannelRedirect() same-origin violation
MFSA 2008-37 / CVE-2008-0016: UTF-8 URL stack buffer
overflow
For more details:
http://www.mozilla.org/security/known-vulnerabilities/thunde
rbird20.html
This update brings Mozilla Thunderbird to version 2.0.0.17.
It contains the following security fixes: MFSA 2008-46 /
CVE-2008-4070: Heap overflow when canceling a newsgroup
message
MFSA 2008-44 / CVE-2008-4067 / CVE-2008-4068: resource:
traversal vulnerabilities
MFSA 2008-43: BOM characters stripped from JavaScript
before execution CVE-2008-4065: Stripped BOM characters bug
CVE-2008-4066: HTML escaped low surrogates bug
MFSA 2008-42 Crashes with evidence of memory corruption
(rv:1.9.0.2/1.8.1.17): CVE-2008-4061: Jesse Ruderman
reported a crash in the layout engine. CVE-2008-4062: Igor
Bukanov, Philip Taylor, Georgi Guninski, and Antoine Labour
reported crashes in the JavaScript engine. CVE-2008-4063:
Jesse Ruderman, Bob Clary, and Martijn Wargers reported
crashes in the layout engine which only affected Firefox 3.
CVE-2008-4064: David Maciejak and Drew Yao reported crashes
in graphics rendering which only affected Firefox 3.
MFSA 2008-41 Privilege escalation via XPCnativeWrapper
pollution CVE-2008-4058: XPCnativeWrapper pollution bugs
CVE-2008-4059: XPCnativeWrapper pollution (Firefox 2)
CVE-2008-4060: Documents without script handling objects
MFSA 2008-38 / CVE-2008-3835:
nsXMLDocument::OnChannelRedirect() same-origin violation
MFSA 2008-37 / CVE-2008-0016: UTF-8 URL stack buffer
overflow
For more details:
http://www.mozilla.org/security/known-vulnerabilities/thunde
rbird20.html
securityMozillaThunderbirdi586c95ea3e0b796c761a39025070f1c9939b202111c469c33552899c995f16f5e0e1f24a9b6833eb26ebc765e0e0495bfc6f21e4631bf2a506e38d3df2eMozillaThunderbirdppca610778404db63cee1bde0716439f6508521945cf35a14d09faa06dd48c74ae1f02aa240f6be81906260def48174bf1338a66fcae615291e2d5f290fMozillaThunderbirdx86_64e41657e93a045bc690f3c864ec0b2bd3de44f38b89acbf3519ab345e4802f0b4f43dc4816f4c7cf87c42d4170a393b4b589ea989a0f88c3836d9b329MozillaThunderbird-translationsi5863e805aa35e0000a076909732cc0ced368572fbf8e1d27dafe525c06f4ab5d89e147d6aeee7bd50b4253a68dc73d3f3fc9fd5499e1554ad7460a0754bMozillaThunderbird-translationsppc2ade805d62a163e7e12a330ceb06c11e81d21add1140024acaa2567807264ca5b430e8e3d73535c3f6f5ab80791a179f0a3f969ada7bd36dab6010d3MozillaThunderbird-translationsx86_64de04a086df9dac61a40b6e5c343b462f3f900d7f0662406324191e052d1e2d1d97a995f2e5156457073eb59d360cba4a41d6151482b89dc9cfebf595