PGP SIGNED MESSAGE
Hash: SHA1
Mandriva Linux Security Advisory MDKSA-2006:146
Package : mozilla-thunderbird
Date : August 21, 2006
Affected: 2006.0, Corporate 3.0
Problem Description:
A number of security vulnerabilities have been discovered and corrected
in the latest Mozilla Thunderbird program.
Corporate 3 had contained the Mozilla suite however, due to the support
cycle for Mozilla, it was felt that upgrading Mozilla to Firefox and
Thunderbird would allow for better future support for Corporate 3
users. To that end, the latest Thunderbird is being provided for
Corporate 3 users which fix all known vulnerabilities up to version
1.5.0.5, as well as providing new and enhanced features.
Corporate users who were using Mozilla for mail may need to explicitly
install the new mozilla-thunderbird packages.
For 2006 users, no explicit installs are necessary.
The following CVE names have been corrected with this update:
CVE-2006-2775, CVE-2006-2776, CVE-2006-2778, CVE-2006-2779,
CVE-2006-2780, CVE-2006-2781, CVE-2006-2783, CVE-2006-2787,
CVE-2006-3803, CVE-2006-3804, CVE-2006-3806, CVE-2006-3807,
CVE-2006-3113, CVE-2006-3802, CVE-2006-3805, CVE-2006-3809,
CVE-2006-3810, CVE-2006-3811, CVE-2006-3812.
References:
Updated Packages:
Mandriva Linux 2006.0:
Mandriva Linux 2006.0/X86_64:
Corporate 3.0:
Corporate 3.0/X86_64:
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
PGP SIGNATURE
Version: GnuPG v1.4.2.2 (GNU/Linux)
nD5cbKR+pVvprv7ysYIq8=
=
PGP SIGNATURE