<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>196481</bug_id>
          
          <creation_ts>2007-10-20 02:22 0000</creation_ts>
          <short_desc>mail-client/mozilla-thunderbird (-bin) &lt; 2.0.0.9 Memory management vulnerabilities (CVE-2007-{5339,5340})</short_desc>
          <delta_ts>2007-11-20 21:29:14 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/27313/</bug_file_loc>
          <status_whiteboard>A2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>199299</blocked>
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>mips@gentoo.org</cc>
    
    <cc>mozilla@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-20 02:22:10 0000</bug_when>
            <thetext>Secunia:
  Some vulnerabilities have been reported in Mozilla Thunderbird,
  which potentially can be exploited by malicious people to compromise
  a user&apos;s system.

  1) Various errors in the browser engine can be exploited to cause
     a memory corruption.
  2) Various errors in the Javascript engine can be exploited to cause
     a memory corruption.
  Successful exploitation of these vulnerabilities may allow execution
  of arbitrary code.

Fixed in Thunderbird 2.0.0.8</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-20 02:23:07 0000</bug_when>
            <thetext>Mozilla, please advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-24 22:29:36 0000</bug_when>
            <thetext>Should we bump the package ourselves? The patches are available without a lot of hassle.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-10-25 06:34:14 0000</bug_when>
            <thetext>In general we should bump packages if maintainers don&apos;t respond in a timely manner. Though we should try to poke them on IRC at least beforehand.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-25 07:32:09 0000</bug_when>
            <thetext>(In reply to comment #3)
&gt; In general we should bump packages if maintainers don&apos;t respond in a timely
&gt; manner. Though we should try to poke them on IRC at least beforehand.

Seems I wasn&apos;t clear enough. I meant we (Gentoo&apos;s mozilla herd) should bump it since Mozilla upstream did not release yet.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-10-25 07:36:19 0000</bug_when>
            <thetext>Oh, I&apos;m confusing roles here. I won&apos;t stand in the way of the herd bumping it&apos;s package:)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-10-25 10:26:28 0000</bug_when>
            <thetext>Where are the patches?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-28 15:07:11 0000</bug_when>
            <thetext>(In reply to comment #6)
&gt; Where are the patches?

Debian ships some for 1.5 which are pretty much undocumented because of the embargo. Ubuntu released a &quot;pre&quot; snapshot. In light of the other regressions you mentioned we should probably wait for upstream.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-11-15 15:11:48 0000</bug_when>
            <thetext>In CVS

To be done:
mail-client/mozilla-thunderbird-2.0.0.9
x11-plugins/enigmail-0.95.3-r1
mail-client/mozilla-thunderbird-bin-2.0.0.9</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-11-15 16:05:58 0000</bug_when>
            <thetext>Arches, please test and mark stable mail-client/mozilla-thunderbird-2.0.0.9.
Target keywords : &quot;alpha amd64 ia64 mips ppc ppc64 sparc x86&quot;

x11-plugins/enigmail-0.95.5-r1.
Target keywords : &quot;alpha amd64 ia64 mips ppc ppc64 sparc x86&quot;

mail-client/mozilla-thunderbird-bin-2.0.0.9:
Target keywords : &quot;amd64 x86&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jackdachef@gmail.com</who>
            <bug_when>2007-11-15 20:21:56 0000</bug_when>
            <thetext>compiled and seems to work fine (still testing):

genlop -t mozilla-thunderbird
 * mail-client/mozilla-thunderbird

     Thu Nov 15 21:17:42 2007 &gt;&gt;&gt; mail-client/mozilla-thunderbird-2.0.0.9
       merge time: 18 minutes and 44 seconds.


Portage 2.1.3.19 (default-linux/amd64/2007.0, gcc-4.2.2, glibc-2.7-r0, 2.6.23-kamikaze5-amd64 x86_64)
=================================================================
System uname: 2.6.23-kamikaze5-amd64 x86_64 Intel(R) Core(TM)2 CPU 6600 @ 2.40GHz
Timestamp of tree: Thu, 15 Nov 2007 19:30:01 +0000
app-shells/bash:     3.2_p17-r1
dev-java/java-config: 1.3.7, 2.1.2-r1
dev-lang/python:     2.4.4-r6
dev-python/pycrypto: 2.0.1-r6
sys-apps/baselayout: 2.0.0_rc6
sys-apps/sandbox:    1.2.18.1-r2
sys-devel/autoconf:  2.13, 2.61-r1
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.16.1-r3, 2.18-r1
sys-devel/gcc-config: 1.4.0-r4
sys-devel/libtool:   1.5.24
virtual/os-headers:  2.6.22-r2
ACCEPT_KEYWORDS=&quot;amd64 ~amd64&quot;
CBUILD=&quot;x86_64-pc-linux-gnu&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2007-11-15 21:16:42 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-11-15 23:47:27 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-11-16 15:48:35 0000</bug_when>
            <thetext>alpha/ia64/sparc stable

i said enigmail-0.95.3-r1, but .5 is fine as well :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-11-18 13:39:29 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-11-18 15:38:06 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-11-18 21:33:45 0000</bug_when>
            <thetext>GLSA 200711-24</thetext>
          </long_desc>
      
    </bug>

</bugzilla>