<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>98855</bug_id>
          
          <creation_ts>2005-07-13 01:04 0000</creation_ts>
          <short_desc>mail-client/mozilla-thunderbird{-bin}: 1.0.5 fixes multiple vulnerabilities</short_desc>
          <delta_ts>2005-07-18 00:58:31 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.mozilla.org/projects/security/known-vulnerabilities.html#Thunderbird</bug_file_loc>
          <status_whiteboard>A2 [glsa] koon</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>koon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>askwar@digitalprojects.com</cc>
    
    <cc>mozilla@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-13 01:04:43 0000</bug_when>
            <thetext>Thunderbird 1.0.5 will fix the following vulnerability :
MFSA 2005-46  XBL scripts ran even when Javascript disabled</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-07-14 01:41:15 0000</bug_when>
            <thetext>1.0.5 released, mozilla please bump.  
 
Note there is still no entry the security page: 
http://www.mozilla.org/projects/security/known-vulnerabilities.html </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-14 03:52:51 0000</bug_when>
            <thetext>Fixed in TB 1.0.5 :

MFSA 2005-56 Code execution through shared function objects
MFSA 2005-55 XHTML node spoofing
MFSA 2005-52 Same origin violation: frame calling top.focus()
MFSA 2005-50 Possibly exploitable crash in InstallVersion.compareTo()
MFSA 2005-46 XBL scripts ran even when Javascript disabled
MFSA 2005-44 Privilege escalation via non-DOM property overrides
MFSA 2005-41 Privilege escalation via DOM property overrides
MFSA 2005-40 Missing Install object instance checks
MFSA 2005-33 Javascript &quot;lambda&quot; replace exposes memory contents
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>geekypenguin@gmail.com</who>
            <bug_when>2005-07-14 09:21:03 0000</bug_when>
            <thetext>mail-client/thunderbird{-bin}: 1.0.5 are in the tree.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-14 10:17:33 0000</bug_when>
            <thetext>Thx Anarchy, arches please test and mark stable :

mozilla-thunderbird target KEYWORDS=&quot;alpha amd64 ia64 ppc sparc x86&quot;
mozilla-thunderbird-bin target KEYWORDS=&quot;~amd64 x86&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>geekypenguin@gmail.com</who>
            <bug_when>2005-07-14 10:40:51 0000</bug_when>
            <thetext>Hold the stable please it is still masked until Aron looks at it and makes a
call on enigmail support. Sorry I should have announced it when I put it up that
they were in the tree.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-14 10:44:34 0000</bug_when>
            <thetext>Waiting for a more definitive ebuild for TB.
x86 can still test TB-bin though.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2005-07-14 10:51:00 0000</bug_when>
            <thetext>i guess amd64 too, right? :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>geekypenguin@gmail.com</who>
            <bug_when>2005-07-14 11:22:25 0000</bug_when>
            <thetext>Aight we have made our finall changes to thunderbird-1.0.5 we can go ahead with
marking stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-14 11:30:29 0000</bug_when>
            <thetext>Calling back arches...
Anarchy will test for ppc.

blubb: TB-bin is ~amd64 so you don&apos;t really need to mark it stable... But you
need to mark TB-not-bin amd64 :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2005-07-14 11:58:25 0000</bug_when>
            <thetext>*** Bug 99031 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>geekypenguin@gmail.com</who>
            <bug_when>2005-07-14 12:26:31 0000</bug_when>
            <thetext>PPC is stable you will need to stabilize mozilla-launcher 0.34 before you can
stablize thunderbird this is fine. Aron and Myself has already discussed this
and do not see any problems.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>humpback@gentoo.org</who>
            <bug_when>2005-07-14 12:43:55 0000</bug_when>
            <thetext>I was actually thinking of marking the -bin stable on amd64 as it works very
well. I&apos;ve already tested the 1.0.5 ond amd64 but i needed that a non ~amd64
user would test and report.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-07-14 12:46:54 0000</bug_when>
            <thetext>I can do the amd64 -bin stable test in about 4 hours when i&apos;m home.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-07-14 17:57:50 0000</bug_when>
            <thetext>sparc stable.
amd64 thunderbird-bin works fine here too (not keywording though since i&apos;m not
on amd64@/authorized/whatever).
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>humpback@gentoo.org</who>
            <bug_when>2005-07-14 18:38:39 0000</bug_when>
            <thetext>-bin stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2005-07-16 16:49:29 0000</bug_when>
            <thetext>Stable on alpha and ia64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-17 10:36:46 0000</bug_when>
            <thetext>x86, amd64: please test and mark thunderbird and thunderbird-bin stable
(thunderbird-bin is already done for amd64)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-17 10:43:23 0000</bug_when>
            <thetext>Hmm. Apparently 1.0.5 is quite broken, 1.0.6 should appear early next week.
http://www.mozillazine.org/talkback.html?article=6950

So I would say, stop the stable marking... and waiting for upstream</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rich0@gentoo.org</who>
            <bug_when>2005-07-17 11:03:34 0000</bug_when>
            <thetext>I&apos;ve been running thunderbird (non-bin, 64-bit-compiled) on amd64 for about 24
hours now without issue.

Oddly enough enigmail seems to be working fine - even though it seems like there
are complaints that it shouldn&apos;t.  Enigmail is installed as a user-profile
extension (ie not system-wide).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>geekypenguin@gmail.com</who>
            <bug_when>2005-07-17 11:12:44 0000</bug_when>
            <thetext>mad64 please mark stable as soon as possible I will handle x86 if noone marks it
by tonight. Enigmail is  NOT suppose to work with thunderbird 1.0.5 but it does
so I do not see this as an issue.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kugelfang@gentoo.org</who>
            <bug_when>2005-07-17 11:35:31 0000</bug_when>
            <thetext>Stable on amd64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>geekypenguin@gmail.com</who>
            <bug_when>2005-07-17 12:51:09 0000</bug_when>
            <thetext>both stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-07-18 00:58:31 0000</bug_when>
            <thetext>GLSA 200507-17</thetext>
          </long_desc>
      
    </bug>

</bugzilla>