<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="b10a2a9334d9b8d94955c5dd39341957"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="MozillaThunderbird-6493"
    timestamp="1253123517"
    engine="1.0">
  <yum:name>MozillaThunderbird</yum:name>
  <summary lang="en">MozillaThunderbird: Security update to version 2.0.0.23</summary>
  <summary lang="de">MozillaThunderbird: Security update to version 2.0.0.23</summary>
  <description lang="en">Mozilla Thunderbird was updated to version 2.0.0.23.

The release fixes one security issue: MFSA 2009-42 /
CVE-2009-2408: IOActive security researcher Dan Kaminsky
reported a mismatch in the treatment of domain names in SSL
certificates between SSL clients and the Certificate
Authorities (CA) which issue server certificates. In
particular, if a malicious person requested a certificate
for a host name with an invalid null character in it most
CAs would issue the certificate if the requester owned the
domain specified after the null, while most SSL clients
(browsers) ignored that part of the name and used the
unvalidated part in front of the null. This made it
possible for attackers to obtain certificates that would
function for any site they wished to target. These
certificates could be used to intercept and potentially
alter encrypted communication between the client and a
server such as sensitive bank account transactions. This
vulnerability was independently reported to us by
researcher Moxie Marlinspike who also noted that since
Firefox relies on SSL to protect the integrity of security
updates this attack could be used to serve malicious
updates.
</description>
  <description lang="de">Mozilla Thunderbird was updated to version 2.0.0.23.

The release fixes one security issue: MFSA 2009-42 /
CVE-2009-2408: IOActive security researcher Dan Kaminsky
reported a mismatch in the treatment of domain names in SSL
certificates between SSL clients and the Certificate
Authorities (CA) which issue server certificates. In
particular, if a malicious person requested a certificate
for a host name with an invalid null character in it most
CAs would issue the certificate if the requester owned the
domain specified after the null, while most SSL clients
(browsers) ignored that part of the name and used the
unvalidated part in front of the null. This made it
possible for attackers to obtain certificates that would
function for any site they wished to target. These
certificates could be used to intercept and potentially
alter encrypted communication between the client and a
server such as sensitive bank account transactions. This
vulnerability was independently reported to us by
researcher Moxie Marlinspike who also noted that since
Firefox relies on SSL to protect the integrity of security
updates this attack could be used to serve malicious
updates.
</description>
  <yum:version ver="6493" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="MozillaThunderbird" epoch="0" ver="2.0.0.23" rel="0.1" flags="EQ"/>
    <rpm:entry kind="atom" name="MozillaThunderbird-devel" epoch="0" ver="2.0.0.23" rel="0.1" flags="EQ"/>
    <rpm:entry kind="atom" name="MozillaThunderbird-translations" epoch="0" ver="2.0.0.23" rel="0.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.0.0.23" rel="0.1"/>
      <checksum type="sha" pkgid="YES">9997cb0830aabd3834265c918c17c8f28ca31600</checksum>
      <time file="1253141734" build="1253123517"/>
      <size package="8840129" installed="29780001" archive="29837744"/>
      <location href="rpm/i586/MozillaThunderbird-2.0.0.23-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird" epoch="0" ver="2.0.0.23" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/i586/MozillaThunderbird-2.0.0.6_2.0.0.23-22_0.1.i586.delta.rpm"/>
          <checksum type="sha">7e418dad5a9e0a379fc2f31e6b0ccf6762baca53</checksum>
          <time file="1253142196" build="1253123517"/>
          <size package="5008057" archive="0"/>
          <base-version epoch="0" ver="2.0.0.6" rel="22" md5sum="8d61454b97195c6d59ad0886ebd1d5a4" buildtime="1190443178" sequence_info="MozillaThunderbird-2.0.0.6-22-86709d7f050e3dcd1e9c8757f6e4e976c2288325174d31822e66b10ca510ba510aa5108d310fc31e310fa31f72"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/MozillaThunderbird-2.0.0.22_2.0.0.23-0.1.i586.delta.rpm"/>
          <checksum type="sha">6fb746c82510965d1da94525847a804212bd419c</checksum>
          <time file="1253142210" build="1253123517"/>
          <size package="762020" archive="0"/>
          <base-version epoch="0" ver="2.0.0.22" rel="0.1" md5sum="5f152afd2e40e46c539323a662f64fc2" buildtime="1247233999" sequence_info="MozillaThunderbird-2.0.0.22-0.1-d99938830f3beb7a5b62ad5f5543df03c2288325174d31822e66b10ca510ba510aa5108d310fc31e310fa31f72"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird</name>
      <arch>ppc</arch>
      <version epoch="0" ver="2.0.0.23" rel="0.1"/>
      <checksum type="sha" pkgid="YES">95d7fb6a0122cd104cc89dabd7552121884376cb</checksum>
      <time file="1253141813" build="1253128387"/>
      <size package="8932948" installed="32732813" archive="32790556"/>
      <location href="rpm/ppc/MozillaThunderbird-2.0.0.23-0.1.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird" epoch="0" ver="2.0.0.23" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/ppc/MozillaThunderbird-2.0.0.6_2.0.0.23-22_0.1.ppc.delta.rpm"/>
          <checksum type="sha">b2fb14e580195aabd00d2342da26786b797bca8f</checksum>
          <time file="1253142271" build="1253128387"/>
          <size package="4950780" archive="0"/>
          <base-version epoch="0" ver="2.0.0.6" rel="22" md5sum="01d0ca86496e03d803052b34e3eb267f" buildtime="1190469307" sequence_info="MozillaThunderbird-2.0.0.6-22-8fcff5c35855c778354794947ae599a4c2288325174d31822e66b10ca510ba510aa5108d310fc31e310fa31f72"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/ppc/MozillaThunderbird-2.0.0.22_2.0.0.23-0.1.ppc.delta.rpm"/>
          <checksum type="sha">4b4d877e623105c6ddafa9281a1d0b5c452a74cf</checksum>
          <time file="1253142285" build="1253128387"/>
          <size package="610945" archive="0"/>
          <base-version epoch="0" ver="2.0.0.22" rel="0.1" md5sum="98213cacd32d30288ee4e875ba893620" buildtime="1247234816" sequence_info="MozillaThunderbird-2.0.0.22-0.1-4c4c41faceb4dc63a34eb962767a8466c2288325174d31822e66b10ca510ba510aa5108d310fc31e310fa31f72"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.0.0.23" rel="0.1"/>
      <checksum type="sha" pkgid="YES">6710b56c675fb942d5bcbb326f014851f7ec1f47</checksum>
      <time file="1253141687" build="1253122574"/>
      <size package="10147620" installed="34050046" archive="34108500"/>
      <location href="rpm/x86_64/MozillaThunderbird-2.0.0.23-0.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird" epoch="0" ver="2.0.0.23" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/x86_64/MozillaThunderbird-2.0.0.6_2.0.0.23-22_0.1.x86_64.delta.rpm"/>
          <checksum type="sha">ed308dac2031ae2bf85459bdd96660eb4055de24</checksum>
          <time file="1253142332" build="1253122574"/>
          <size package="6407802" archive="0"/>
          <base-version epoch="0" ver="2.0.0.6" rel="22" md5sum="ba0b6a601a6925bdf7ef8480b2d43a20" buildtime="1190434797" sequence_info="MozillaThunderbird-2.0.0.6-22-a856bf92b480e74f2b70e595e9500316c2288325174d31822e66b10ca510ba510aa5108d310fc31e310fa31f72"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/x86_64/MozillaThunderbird-2.0.0.22_2.0.0.23-0.1.x86_64.delta.rpm"/>
          <checksum type="sha">761de9464b808f002b37438ab3b28105882c3f90</checksum>
          <time file="1253142351" build="1253122574"/>
          <size package="1054507" archive="0"/>
          <base-version epoch="0" ver="2.0.0.22" rel="0.1" md5sum="7f30989f75a249420e283026ae7f0f18" buildtime="1247233069" sequence_info="MozillaThunderbird-2.0.0.22-0.1-b11a502e60eb9ee4626b0337b537eff7c2288325174d31822e66b10ca510ba510aa5108d310fc31e310fa31f72"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.0.0.23" rel="0.1"/>
      <checksum type="sha" pkgid="YES">ba129d114308e9553d21494c5e19f7032eb4ca33</checksum>
      <time file="1253141741" build="1253123517"/>
      <size package="3135550" installed="22992067" archive="23725196"/>
      <location href="rpm/i586/MozillaThunderbird-devel-2.0.0.23-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird-devel" epoch="0" ver="2.0.0.23" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/i586/MozillaThunderbird-devel-2.0.0.22_2.0.0.23-0.1.i586.delta.rpm"/>
          <checksum type="sha">21fed9aa197bde727e0ed699e5505da6aa199808</checksum>
          <time file="1253142384" build="1253123517"/>
          <size package="464357" archive="0"/>
          <base-version epoch="0" ver="2.0.0.22" rel="0.1" md5sum="46857525c48cbf162f6c61cfae88039d" buildtime="1247233999" sequence_info="MozillaThunderbird-devel-2.0.0.22-0.1-0d3d58af977dd2aa49f7eef925a8c9558ec12ef8709ec110"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird-devel</name>
      <arch>ppc</arch>
      <version epoch="0" ver="2.0.0.23" rel="0.1"/>
      <checksum type="sha" pkgid="YES">c3406c88a0344bd531242e4a0bc338e07b951da5</checksum>
      <time file="1253141825" build="1253128387"/>
      <size package="3047775" installed="22925120" archive="23494200"/>
      <location href="rpm/ppc/MozillaThunderbird-devel-2.0.0.23-0.1.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird-devel" epoch="0" ver="2.0.0.23" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/ppc/MozillaThunderbird-devel-2.0.0.22_2.0.0.23-0.1.ppc.delta.rpm"/>
          <checksum type="sha">38812ef7a094876647dca5a649b280f5df379b23</checksum>
          <time file="1253142399" build="1253128387"/>
          <size package="377950" archive="0"/>
          <base-version epoch="0" ver="2.0.0.22" rel="0.1" md5sum="0d7769118179569bbbe5c35000fa70e9" buildtime="1247234816" sequence_info="MozillaThunderbird-devel-2.0.0.22-0.1-ca8f2d4267737d16bb1bc05e90ef4daf8ec12fc9509ec110"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.0.0.23" rel="0.1"/>
      <checksum type="sha" pkgid="YES">8dabae5731b785f27b6451a4342f37f07cb32d75</checksum>
      <time file="1253141691" build="1253122574"/>
      <size package="3047690" installed="22945494" archive="23514596"/>
      <location href="rpm/x86_64/MozillaThunderbird-devel-2.0.0.23-0.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird-devel" epoch="0" ver="2.0.0.23" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/x86_64/MozillaThunderbird-devel-2.0.0.22_2.0.0.23-0.1.x86_64.delta.rpm"/>
          <checksum type="sha">7100653dfa135c88689924c036e9943e4afe0194</checksum>
          <time file="1253142412" build="1253122574"/>
          <size package="374714" archive="0"/>
          <base-version epoch="0" ver="2.0.0.22" rel="0.1" md5sum="0a5a7e95acc8148fc2d3b07c4ba06c05" buildtime="1247233069" sequence_info="MozillaThunderbird-devel-2.0.0.22-0.1-97e33ca2af33121462ca4cb00b932fc08ec12fc9509ec110"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird-translations</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.0.0.23" rel="0.1"/>
      <checksum type="sha" pkgid="YES">f5097169b4270f6230e9dea7db7a1bc4487c3ef8</checksum>
      <time file="1253141742" build="1253123517"/>
      <size package="4935806" installed="30173155" archive="30184532"/>
      <location href="rpm/i586/MozillaThunderbird-translations-2.0.0.23-0.1.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird-translations" epoch="0" ver="2.0.0.23" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/i586/MozillaThunderbird-translations-2.0.0.6_2.0.0.23-22_0.1.i586.delta.rpm"/>
          <checksum type="sha">f853efb3d956d49a7517096cdbd7625ce8a6243e</checksum>
          <time file="1253142429" build="1253123517"/>
          <size package="384626" archive="0"/>
          <base-version epoch="0" ver="2.0.0.6" rel="22" md5sum="7cfee46bb83598cdacdb89a37cdefbd6" buildtime="1190443178" sequence_info="MozillaThunderbird-translations-2.0.0.6-22-5ad2faef3ff5d234d7436c08dd2545dcc810"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/MozillaThunderbird-translations-2.0.0.22_2.0.0.23-0.1.i586.delta.rpm"/>
          <checksum type="sha">52314605f86353e03146520ebf13b49821a780a9</checksum>
          <time file="1253142438" build="1253123517"/>
          <size package="27666" archive="0"/>
          <base-version epoch="0" ver="2.0.0.22" rel="0.1" md5sum="32046e378dda4e96c5a64483c65eb7f7" buildtime="1247233999" sequence_info="MozillaThunderbird-translations-2.0.0.22-0.1-aed83ba37c21bfb1027862421fafd0cca910"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird-translations</name>
      <arch>ppc</arch>
      <version epoch="0" ver="2.0.0.23" rel="0.1"/>
      <checksum type="sha" pkgid="YES">cac9df7ddf43ba34403bc7ff7fbf2e7a230e6da1</checksum>
      <time file="1253141826" build="1253128387"/>
      <size package="4936286" installed="30173155" archive="30184532"/>
      <location href="rpm/ppc/MozillaThunderbird-translations-2.0.0.23-0.1.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird-translations" epoch="0" ver="2.0.0.23" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/ppc/MozillaThunderbird-translations-2.0.0.6_2.0.0.23-22_0.1.ppc.delta.rpm"/>
          <checksum type="sha">dbba2f39f050fff4698dee41359022851ee0d5d9</checksum>
          <time file="1253142462" build="1253128387"/>
          <size package="384931" archive="0"/>
          <base-version epoch="0" ver="2.0.0.6" rel="22" md5sum="7f8048801e7a9ea0d3efcd8de69154d6" buildtime="1190469307" sequence_info="MozillaThunderbird-translations-2.0.0.6-22-5ad2faef3ff5d234d7436c08dd2545dcc810"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/ppc/MozillaThunderbird-translations-2.0.0.22_2.0.0.23-0.1.ppc.delta.rpm"/>
          <checksum type="sha">b8cc4994aa017041e25dcd6a2b76b8b654e8698b</checksum>
          <time file="1253142470" build="1253128387"/>
          <size package="27797" archive="0"/>
          <base-version epoch="0" ver="2.0.0.22" rel="0.1" md5sum="e8381af5092b4edba08849d82fb6781f" buildtime="1247234816" sequence_info="MozillaThunderbird-translations-2.0.0.22-0.1-aed83ba37c21bfb1027862421fafd0cca910"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird-translations</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="2.0.0.23" rel="0.1"/>
      <checksum type="sha" pkgid="YES">c3cb6a5d321e0122058248679a3226974e5efba6</checksum>
      <time file="1253141691" build="1253122574"/>
      <size package="4935239" installed="30173155" archive="30184632"/>
      <location href="rpm/x86_64/MozillaThunderbird-translations-2.0.0.23-0.1.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird-translations" epoch="0" ver="2.0.0.23" rel="0.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <deltarpm>
          <location href="rpm/x86_64/MozillaThunderbird-translations-2.0.0.6_2.0.0.23-22_0.1.x86_64.delta.rpm"/>
          <checksum type="sha">5436ab36934df193037a7ea8ab5730a1f7bddfed</checksum>
          <time file="1253142493" build="1253122574"/>
          <size package="384876" archive="0"/>
          <base-version epoch="0" ver="2.0.0.6" rel="22" md5sum="536e22d9fd08d4e5f142c19547f720c4" buildtime="1190434797" sequence_info="MozillaThunderbird-translations-2.0.0.6-22-a857f53a26a394093efc5752b9ab7eadc810"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/x86_64/MozillaThunderbird-translations-2.0.0.22_2.0.0.23-0.1.x86_64.delta.rpm"/>
          <checksum type="sha">263c41fab5cd6c9058bef7b15a1c3c39d4abb8ed</checksum>
          <time file="1253142501" build="1253122574"/>
          <size package="27736" archive="0"/>
          <base-version epoch="0" ver="2.0.0.22" rel="0.1" md5sum="04e150503d18a9d950c914adbf6d8b4a" buildtime="1247233069" sequence_info="MozillaThunderbird-translations-2.0.0.22-0.1-b32b3305ec624b3e1964d993dfc3b24da910"/>
        </deltarpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
