[thunderbird] [CVE-2008-0591] missing fix in USN-582-1/2?

Bug #199412 reported by disabled.user
256
Affects Status Importance Assigned to Milestone
thunderbird (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: thunderbird

It seems like the latest USN for Thunderbird (see USN-582-1 and USN-582-2) misses a fix for CVE-2008-0591 when compared to:
- DSA-1485-1 (http://www.debian.org/security/2008/dsa-1485)
- MDVSA-2008:062 (http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:062)

If Ubuntu's Thunderbird is not affected by CVE-2008-0591, then sorry for reporting this, but I thought "better safe than sorry".

Related branches

CVE References

description: updated
Daniel T Chen (crimsun)
Changed in thunderbird:
status: New → Confirmed
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

The MFSA states that this only affected Firefox:
http://www.mozilla.org/security/announce/2008/mfsa2008-08.html

However the CVE lists Thunderbird below 2.0.0.12 is affected.

Alexander, is Thunderbird actually affected by this and in which update? I can update the USN accordingly if Thunderbird is affected.

Revision history for this message
Alexander Sack (asac) wrote : Re: [Bug 199412] Re: [thunderbird] [CVE-2008-0591] missing fix in USN-582-1/2?

On Tue, Dec 02, 2008 at 04:37:57PM -0000, Jamie Strandboge wrote:
> The MFSA states that this only affected Firefox:
> http://www.mozilla.org/security/announce/2008/mfsa2008-08.html
>
> However the CVE lists Thunderbird below 2.0.0.12 is affected.
>
> Alexander, is Thunderbird actually affected by this and in which update?
> I can update the USN accordingly if Thunderbird is affected.
>

Not sure why it wasnt declared to affect tbird. However, we have the
patch in both: tbird 2 and in 1.5 branch used in dapper ... so we
should be save.

 - Alexander

Changed in thunderbird:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.