<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>109094</bug_id>
          
          <creation_ts>2005-10-13 00:56 0000</creation_ts>
          <short_desc>mail-client/mozilla-thunderbird{-bin}: does 1.0.7 fixes vulnerabilities ?</short_desc>
          <delta_ts>2005-10-18 05:38:05 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WORKSFORME</resolution>
          <bug_file_loc>http://www.mozilla.org/projects/security/known-vulnerabilities.html#Thunderbird</bug_file_loc>
          <status_whiteboard>A2? [noglsa] koon</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>koon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          

      

      
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-13 00:56:06 0000</bug_when>
            <thetext>Thunderbird might be vulnerable to more than just the Mozilla Foundation says
(it might be vuylnerable to much of the recent Firefox issues). At least
Madriva, RedHat and Ubuntu are quite convinced of this.

I asked for details, opening a bug do keep track of the issue.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-13 01:05:36 0000</bug_when>
            <thetext>Testing and marking those stable preventively might be a good idea :

mozilla-thunderbird Target KEYWORDS=&quot;alpha amd64 ia64 ppc sparc x86&quot;
mozilla-thunderbird-bin Target KEYWORDS=&quot;amd64 x86&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-10-13 11:21:15 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fuzzyray@gentoo.org</who>
            <bug_when>2005-10-13 14:46:49 0000</bug_when>
            <thetext>Stable on x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hparker@gentoo.org</who>
            <bug_when>2005-10-13 18:58:03 0000</bug_when>
            <thetext>mozilla-thunderbird ok on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bugs@braingravy.co.uk</who>
            <bug_when>2005-10-13 23:04:36 0000</bug_when>
            <thetext>(In reply to comment #4)
&gt; mozilla-thunderbird ok on amd64

Shouldn&apos;t thunderbird-bin also be marked stable on AMD64?

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-14 00:31:49 0000</bug_when>
            <thetext>(In reply to comment #5)
&gt; 
&gt; Shouldn&apos;t thunderbird-bin also be marked stable on AMD64?

Yes it should.

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2005-10-14 01:40:19 0000</bug_when>
            <thetext>-bin stable too on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>yoswink@gentoo.org</who>
            <bug_when>2005-10-15 06:44:11 0000</bug_when>
            <thetext>Alpha Stable ( 1.0.7 )

BTW, ia64 seems to be done and keyworded by agriffis (please Aron, CC&apos;ed ia64
again if needed).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>josejx@gentoo.org</who>
            <bug_when>2005-10-15 13:19:08 0000</bug_when>
            <thetext>Marked ppc stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-16 02:02:07 0000</bug_when>
            <thetext>Ready for GLSA, waiting for more information about vulnerability of TB.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-18 05:38:05 0000</bug_when>
            <thetext>Here is the results of our ivestigation, thanks to Josh Bressers of RedHat :

- The XBM image decoder issue does not affect Thunderbird.
- The zero-width non-joiner sequences can just be used to crash TB
- The other flaws need Javascript (off in Thunderbird)

So I&apos;ll close this one as WORKSFORME. Feel free to reopen if you disagree.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>