Nom du paquet
mozilla-thunderbird
Date
2010-03-01
Advisory ID
MDVSA-2010:051
Affected versions
2010.0 x86_64 , 2010.0 i586 , 2009.1 i586 , 2009.1 x86_64 , 2008.0 x86_64 , 2008.0 i586

Problem description

A vulnerabilitiy has been found and corrected in mozilla-thunderbird:

Security researcher Alin Rad Pop of Secunia Research reported that
the HTML parser incorrectly freed used memory when insufficient space
was available to process remaining input. Under such circumstances,
memory occupied by in-use objects was freed and could later be filled
with attacker-controlled text. These conditions could result in the
execution or arbitrary code if methods on the freed objects were
subsequently called (CVE-2009-1571).

Packages for 2008.0 are provided for Corporate Desktop 2008.0
customers.

The updated packages have been patched to correct this issue.

Updated packages

2010.0 x86_64

 9237ccb3f2930777857bf4e2e9316b19  2010.0/x86_64/mozilla-thunderbird-2.0.0.23-3.3mdv2010.0.x86_64.rpm
 e5fba2b9e3b714887cfef59028c58da0  2010.0/x86_64/mozilla-thunderbird-devel-2.0.0.23-3.3mdv2010.0.x86_64.rpm
 f1e53699bf38123350a4cde8ad89a506  2010.0/x86_64/mozilla-thunderbird-enigmail-2.0.0.23-3.3mdv2010.0.x86_64.rpm
 099f31525f8a73242481bc121a05f811  2010.0/x86_64/nsinstall-2.0.0.23-3.3mdv2010.0.x86_64.rpm 
 62a8bf250e22e2bd78f0cb2baa0199d1  2010.0/SRPMS/mozilla-thunderbird-2.0.0.23-3.3mdv2010.0.src.rpm

2010.0 i586

 9ef8f1537843b2c490ca143f3483ff90  2010.0/i586/mozilla-thunderbird-2.0.0.23-3.3mdv2010.0.i586.rpm
 c79d2b30bacc364d332369b5af9bdd63  2010.0/i586/mozilla-thunderbird-devel-2.0.0.23-3.3mdv2010.0.i586.rpm
 ba2eb612b17795a6c0bbbde7494a14d3  2010.0/i586/mozilla-thunderbird-enigmail-2.0.0.23-3.3mdv2010.0.i586.rpm
 6df1a02ac8002218f5b1e47a2fff9925  2010.0/i586/nsinstall-2.0.0.23-3.3mdv2010.0.i586.rpm 
 62a8bf250e22e2bd78f0cb2baa0199d1  2010.0/SRPMS/mozilla-thunderbird-2.0.0.23-3.3mdv2010.0.src.rpm

2009.1 i586

 d68983379c1ca52f6c0a4175e79cd640  2009.1/i586/mozilla-thunderbird-2.0.0.23-0.4mdv2009.1.i586.rpm
 9e89756f135bdaa72bf6b511ee667ead  2009.1/i586/mozilla-thunderbird-devel-2.0.0.23-0.4mdv2009.1.i586.rpm
 bbf5f3bda970bb86ce55b66e12e64907  2009.1/i586/mozilla-thunderbird-enigmail-2.0.0.23-0.4mdv2009.1.i586.rpm
 c1a46fbffdd4d2fc5c101fcc55b902b6  2009.1/i586/nsinstall-2.0.0.23-0.4mdv2009.1.i586.rpm 
 72d65ce1a53e8844e8c71f621fdadc18  2009.1/SRPMS/mozilla-thunderbird-2.0.0.23-0.4mdv2009.1.src.rpm

2009.1 x86_64

 802e7555022b4baf6f28269f04682bce  2009.1/x86_64/mozilla-thunderbird-2.0.0.23-0.4mdv2009.1.x86_64.rpm
 122a5efa00ccc3dafbe270f14a1962cf  2009.1/x86_64/mozilla-thunderbird-devel-2.0.0.23-0.4mdv2009.1.x86_64.rpm
 49fb3867b121998c86c120ae42d4b9fc  2009.1/x86_64/mozilla-thunderbird-enigmail-2.0.0.23-0.4mdv2009.1.x86_64.rpm
 6f9df106772918d05836526a11f40e16  2009.1/x86_64/nsinstall-2.0.0.23-0.4mdv2009.1.x86_64.rpm 
 72d65ce1a53e8844e8c71f621fdadc18  2009.1/SRPMS/mozilla-thunderbird-2.0.0.23-0.4mdv2009.1.src.rpm

2008.0 x86_64

 6172c6e7d8852d8ec73b29ae814417fe  2008.0/x86_64/mozilla-thunderbird-2.0.0.23-1.3mdv2008.0.x86_64.rpm
 e691518e1dd9120b3ec55cc80af4e928  2008.0/x86_64/mozilla-thunderbird-devel-2.0.0.23-1.3mdv2008.0.x86_64.rpm
 a30f96d07eea85b6678d3469a5b88f91  2008.0/x86_64/mozilla-thunderbird-enigmail-2.0.0.23-1.3mdv2008.0.x86_64.rpm
 81b4ddb1e4eecc848c4cbc37bd3f4b87  2008.0/x86_64/nsinstall-2.0.0.23-1.3mdv2008.0.x86_64.rpm 
 4abdb45fe3d2091d6aeb84094d8ac1a2  2008.0/SRPMS/mozilla-thunderbird-2.0.0.23-1.3mdv2008.0.src.rpm

2008.0 i586

 2669429882c6f2d4f896007a4b81c0cc  2008.0/i586/mozilla-thunderbird-2.0.0.23-1.3mdv2008.0.i586.rpm
 8ab5c1d63809c1cbc46f52de0afc053f  2008.0/i586/mozilla-thunderbird-devel-2.0.0.23-1.3mdv2008.0.i586.rpm
 c40f64b4e053d51df02c23d777615f9c  2008.0/i586/mozilla-thunderbird-enigmail-2.0.0.23-1.3mdv2008.0.i586.rpm
 f43d572170fec137873c42c698abba4d  2008.0/i586/nsinstall-2.0.0.23-1.3mdv2008.0.i586.rpm 
 4abdb45fe3d2091d6aeb84094d8ac1a2  2008.0/SRPMS/mozilla-thunderbird-2.0.0.23-1.3mdv2008.0.src.rpm

References