[rock-user] [Security Announcement] thunderbird (RLSA-20060322-02)

"Daniel Jahre" <[email protected]> Wed, 22 Mar 2006 17:37:09 +0100
Newsgroups gmane.linux.distributions.rock.user
Message-ID <[email protected]>
This is a ROCK Linux Security Announcement.

Package: thunderbird
Announcement ID: RLSA-20060322-02
Date: 2006-03-22
Affected Distributions: Crystal, LiveCD
Affected Releases: Crystal ROCK CLT
Cross References: MDKSA-2006:052, CVE-2006-0884

Content of this advisory:
1) Problem Description
2) Solution or Work-Around
3) Special instructions and notes
4) Updateing your source tree
5) Source package update
6) Binary package update

--------------------------------------------------------------------------------

1) Problem Description
The WYSIWYG rendering engine in Mozilla Thunderbird 1.0.7 and earlier
allows user-complicit attackers to bypass javascript security settings
and obtain sensitive information or cause a crash via an e-mail
containing a javascript URI in the SRC attribute of an IFRAME tag,
which is executed when the user edits the e-mail.

2) Solution or Workaround
There is no known Work-Around. Please update this package to version 1.5

3) Special instruction and notes
none

4) Updateing your source tree
If you are using a subversion checkout of trunk, run:
  svn up

If you are using submaster run,
 sm sync
to merge the update from trunk into your tree

5) Source package update
As a user of an affected distribution you can update this package by
rebuilding it on your machine
run
  rocket updsrc
to update your local sources and
  rocket emerge thunderbird
to install the updated package

6) Binary package update
there are no new binary packages available for this package yet.