<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="48fcbb624a95b290275340017ad12e5c"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="236">
  <id>MozillaThunderbird</id>
  <title>MozillaThunderbird: Security update to 2.0.0.17</title>
  <release>openSUSE 11.0</release>
  <issued date="1223007401"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=429179" id="429179" title="bug number 429179" type="bugzilla"/>
  </references>
  <description>This update brings Mozilla Thunderbird to version 2.0.0.17.

It contains the following security fixes: MFSA 2008-46 /
CVE-2008-4070: Heap overflow when canceling a newsgroup
message

MFSA 2008-44 / CVE-2008-4067 / CVE-2008-4068: resource:
traversal vulnerabilities

MFSA 2008-43: BOM characters stripped from JavaScript
before execution CVE-2008-4065: Stripped BOM characters bug
CVE-2008-4066: HTML escaped low surrogates bug

MFSA 2008-42 Crashes with evidence of memory corruption
(rv:1.9.0.2/1.8.1.17): CVE-2008-4061: Jesse Ruderman
reported a crash in the layout engine. CVE-2008-4062: Igor
Bukanov, Philip Taylor, Georgi Guninski, and Antoine Labour
reported crashes in the JavaScript engine. CVE-2008-4063:
Jesse Ruderman, Bob Clary, and Martijn Wargers reported
crashes in the layout engine which only affected Firefox 3.
CVE-2008-4064: David Maciejak and Drew Yao reported crashes
in graphics rendering which only affected Firefox 3.

MFSA 2008-41 Privilege escalation via XPCnativeWrapper
pollution CVE-2008-4058: XPCnativeWrapper pollution bugs
CVE-2008-4059: XPCnativeWrapper pollution (Firefox 2)
CVE-2008-4060: Documents without script handling objects

MFSA 2008-38 / CVE-2008-3835:
nsXMLDocument::OnChannelRedirect() same-origin violation

MFSA 2008-37 / CVE-2008-0016: UTF-8 URL stack buffer
overflow

For more details:
http://www.mozilla.org/security/known-vulnerabilities/thunde
rbird20.html
</description>
  <pkglist>
    <collection>
        <package name="MozillaThunderbird" arch="i586" version="2.0.0.17" release="0.1">
          <filename>MozillaThunderbird-2.0.0.17-0.1.i586.rpm</filename>
        </package>
        <package name="MozillaThunderbird" arch="ppc" version="2.0.0.17" release="0.1">
          <filename>MozillaThunderbird-2.0.0.17-0.1.ppc.rpm</filename>
        </package>
        <package name="MozillaThunderbird" arch="x86_64" version="2.0.0.17" release="0.1">
          <filename>MozillaThunderbird-2.0.0.17-0.1.x86_64.rpm</filename>
        </package>
        <package name="MozillaThunderbird-devel" arch="i586" version="2.0.0.17" release="0.1">
          <filename>MozillaThunderbird-devel-2.0.0.17-0.1.i586.rpm</filename>
        </package>
        <package name="MozillaThunderbird-devel" arch="ppc" version="2.0.0.17" release="0.1">
          <filename>MozillaThunderbird-devel-2.0.0.17-0.1.ppc.rpm</filename>
        </package>
        <package name="MozillaThunderbird-devel" arch="x86_64" version="2.0.0.17" release="0.1">
          <filename>MozillaThunderbird-devel-2.0.0.17-0.1.x86_64.rpm</filename>
        </package>
        <package name="MozillaThunderbird-translations" arch="i586" version="2.0.0.17" release="0.1">
          <filename>MozillaThunderbird-translations-2.0.0.17-0.1.i586.rpm</filename>
        </package>
        <package name="MozillaThunderbird-translations" arch="ppc" version="2.0.0.17" release="0.1">
          <filename>MozillaThunderbird-translations-2.0.0.17-0.1.ppc.rpm</filename>
        </package>
        <package name="MozillaThunderbird-translations" arch="x86_64" version="2.0.0.17" release="0.1">
          <filename>MozillaThunderbird-translations-2.0.0.17-0.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
