blob: cb3a09cc96f4526553607faec6d5e6d6e8124363 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<TITLE> [Mageia-dev] Freeze push request: thunderbird and thunderbird-l10n
</TITLE>
<LINK REL="Index" HREF="index.html" >
<LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Freeze%20push%20request%3A%20thunderbird%20and%20thunderbird-l10n&In-Reply-To=%3C4F998D3C.3070902%40arcor.de%3E">
<META NAME="robots" CONTENT="index,nofollow">
<META http-equiv="Content-Type" content="text/html; charset=us-ascii">
<LINK REL="Previous" HREF="014905.html">
<LINK REL="Next" HREF="014906.html">
</HEAD>
<BODY BGCOLOR="#ffffff">
<H1>[Mageia-dev] Freeze push request: thunderbird and thunderbird-l10n</H1>
<B>Florian Hubold</B>
<A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Freeze%20push%20request%3A%20thunderbird%20and%20thunderbird-l10n&In-Reply-To=%3C4F998D3C.3070902%40arcor.de%3E"
TITLE="[Mageia-dev] Freeze push request: thunderbird and thunderbird-l10n">doktor5000 at arcor.de
</A><BR>
<I>Thu Apr 26 20:00:28 CEST 2012</I>
<P><UL>
<LI>Previous message: <A HREF="014905.html">[Mageia-dev] freeze push: drakx-installer-images
</A></li>
<LI>Next message: <A HREF="014906.html">[Mageia-dev] Freeze push request: thunderbird and thunderbird-l10n
</A></li>
<LI> <B>Messages sorted by:</B>
<a href="date.html#14903">[ date ]</a>
<a href="thread.html#14903">[ thread ]</a>
<a href="subject.html#14903">[ subject ]</a>
<a href="author.html#14903">[ author ]</a>
</LI>
</UL>
<HR>
<!--beginarticle-->
<PRE>Hi,
please push thunderbird and thunderbird-l10n,
was just updated to 10.0.4ESR and fixes the following issues:
o fixes <A HREF="http://www.mozilla.org/security/announce/2012/mfsa2012-20.html">http://www.mozilla.org/security/announce/2012/mfsa2012-20.html</A>
(Miscellaneous memory safety hazards [CVE-2012-0468, CVE-2012-0467])
o fixes <A HREF="http://www.mozilla.org/security/announce/2012/mfsa2012-22.html">http://www.mozilla.org/security/announce/2012/mfsa2012-22.html</A>
(use-after-free in IDBKeyRange[CVE-2012-0469])
o fixes <A HREF="http://www.mozilla.org/security/announce/2012/mfsa2012-23.html">http://www.mozilla.org/security/announce/2012/mfsa2012-23.html</A>
(Invalid frees causes heap corruption in gfxImageSurface [CVE-2012-0470])
o fixes <A HREF="http://www.mozilla.org/security/announce/2012/mfsa2012-24.html">http://www.mozilla.org/security/announce/2012/mfsa2012-24.html</A>
(Potential XSS via multibyte content processing errors [CVE-2012-0471])
o fixes <A HREF="http://www.mozilla.org/security/announce/2012/mfsa2012-25.html">http://www.mozilla.org/security/announce/2012/mfsa2012-25.html</A>
(Potential memory corruption during font rendering using cairo-dwrite
[CVE-2012-0472])
o fixes <A HREF="http://www.mozilla.org/security/announce/2012/mfsa2012-26.html">http://www.mozilla.org/security/announce/2012/mfsa2012-26.html</A>
(WebGL.drawElements may read illegal video memory due to
FindMaxUshortElement error [CVE-2012-0473])
o fixes <A HREF="http://www.mozilla.org/security/announce/2012/mfsa2012-27.html">http://www.mozilla.org/security/announce/2012/mfsa2012-27.html</A>
(Page load short-circuit can lead to XSS [CVE-2012-0474])
o fixes <A HREF="http://www.mozilla.org/security/announce/2012/mfsa2012-28.html">http://www.mozilla.org/security/announce/2012/mfsa2012-28.html</A>
(Ambiguous IPv6 in Origin headers may bypass webserver access restrictions
[CVE-2012-0475])
o fixes <A HREF="http://www.mozilla.org/security/announce/2012/mfsa2012-29.html">http://www.mozilla.org/security/announce/2012/mfsa2012-29.html</A>
(Potential XSS through ISO-2022-KR/ISO-2022-CN decoding issues
[CVE-2012-0477])
o fixes <A HREF="http://www.mozilla.org/security/announce/2012/mfsa2012-30.html">http://www.mozilla.org/security/announce/2012/mfsa2012-30.html</A>
(Crash with WebGL content using textImage2D [CVE-2012-0478])
o fixes <A HREF="http://www.mozilla.org/security/announce/2012/mfsa2012-31.html">http://www.mozilla.org/security/announce/2012/mfsa2012-31.html</A>
(Off-by-one error in OpenType Sanitizer [CVE-2011-3062])
o fixes <A HREF="http://www.mozilla.org/security/announce/2012/mfsa2012-33.html">http://www.mozilla.org/security/announce/2012/mfsa2012-33.html</A>
(Potential site identity spoofing when loading RSS and Atom feeds
[CVE-2012-0479])
- switch to Enigmail 1.4, officially supported version for ESR releases
o fixes a problem with inline PGP decrpytion
Kind Regards
</PRE>
<!--endarticle-->
<HR>
<P><UL>
<!--threads-->
<LI>Previous message: <A HREF="014905.html">[Mageia-dev] freeze push: drakx-installer-images
</A></li>
<LI>Next message: <A HREF="014906.html">[Mageia-dev] Freeze push request: thunderbird and thunderbird-l10n
</A></li>
<LI> <B>Messages sorted by:</B>
<a href="date.html#14903">[ date ]</a>
<a href="thread.html#14903">[ thread ]</a>
<a href="subject.html#14903">[ subject ]</a>
<a href="author.html#14903">[ author ]</a>
</LI>
</UL>
<hr>
<a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev
mailing list</a><br>
</body></html>
|