update to thunderbird 1.5.0.2

Bug #41096 reported by Pavel Rojtberg
266
Affects Status Importance Assigned to Milestone
mozilla-thunderbird (Ubuntu)
Fix Released
Critical
Adam Conrad

Bug Description

I'm using thunderbird to share my mails between windows and ubuntu.
But on windows I'm running version 1.5.0.2, since it has some security updates.
I dont know whether the ubuntu packages already include them, but my main problem is that thunderbird recognizes the different version between both systems and checks for "extension updates" every time I start it after rebooting.

Revision history for this message
Bruce Cowan (bruce89-deactivatedaccount) wrote :

http://www.mozilla.com/thunderbird/releases/1.5.0.2.html details some of the improvements, also there are security implications

Changed in mozilla-thunderbird:
status: Unconfirmed → Confirmed
Revision history for this message
Elijah Lofgren (elijahlofgren) wrote :

I sure hope this makes it into Dapper. I needed a bug fix in this version so I installed Thunderbird 1.5.0.2 from the Mozilla site. It would be nice if I could install it from the Ubuntu repositories.

Revision history for this message
Daniel Eckl (daniel-eckl) wrote :

Is there any known reason for not updating thunderbird to 1.5.0.2?
Thunderbird before this version is known to have multiple security issues:
http://www.mozilla.org/projects/security/known-vulnerabilities.html#thunderbird1.5.0.2
Two of them have critical impact!
I will raise severity and assign to maintainer until further info from him.
Sorry for making such noise, but if there are any reasons for delaying a security update, they should be given here. And having release in two weeks is not a reason against the update, but _for_ it.
Best, Daniel

Changed in mozilla-thunderbird:
assignee: nobody → asac
Revision history for this message
Elijah Lofgren (elijahlofgren) wrote :

Thanks Daniel,

I hope 1.5.0.2 makes it into Dapper.

Hopefully then the easy answer to the LONG running thread on installing Thunderbird 1.5.0.2 ( http://www.ubuntuforums.org/showthread.php?t=165655 ) will just be to install Dapper and install updated thunderbird package from Ubuntu repositories.

Revision history for this message
Adam Conrad (adconrad) wrote :

Please don't reassign bugs willy-nilly if you're not A) a release manager, or B) someone claiming the bug for yourself.

asac does a lot of great work on Thunderbird in Debian, but it's not his responsibility in Ubuntu.

Changed in mozilla-thunderbird:
assignee: asac → adconrad
Revision history for this message
Daniel Eckl (daniel-eckl) wrote :

Hi Adam!

I apologize for the false assignment.

If Alexander is the maintainer for debian but not for ubuntu, then the paket mozilla-thunderbird-1.5-0ubuntu6 has a wrong maintainer. But perhaps I don't understand the meaning of the maintainer field fully.

But I'm happy that this bug now has the focus of the correct person which was not the case before my false assignment.

Thank you and please don't be upset,
Daniel

Revision history for this message
Sarah Kowalik (hobbsee-deactivatedaccount) wrote :

https://lists.ubuntu.com/archives/dapper-changes/2006-May/011171.html

This seems to now be fixed, according to the dapper changes, and apt-cache.

Please reopen if this is not the case.

Changed in mozilla-thunderbird:
status: Confirmed → Fix Released
Revision history for this message
Daniel Eckl (daniel-eckl) wrote :

I can confirm that on my machine. Thank you Adam and Hobbsee!

I hope that security updates to this often used and security sensitive application are processed faster after dapper release.

Best,
Daniel

Revision history for this message
Adam Conrad (adconrad) wrote :

Daniel, you may want to note that the "Maintainer" field in Ubuntu is pretty much meaningless, since we tend to inherit it from Debian sources we import, but there are a much (MUCH) smaller number of us than there are Debian maintainers and we don't generally "own" many packages, but just "make stuff work" in general.

Revision history for this message
Daniel Eckl (daniel-eckl) wrote :

Ah okay. I didn't really thought of that possibility. Until now I thought that packages with the string "ubuntu" in it were natively from the ubuntu team.
Thank you for sheding light on that issue.

Revision history for this message
Adam Conrad (adconrad) wrote :

"ubuntu" in the version means that they're modified, compared to the Debian versions. Sometimes, this is a small bugfix or tweak, sometimes it's us shipping a new upstream before Debian, and sometimes it means we're pretty painfully forked (as is currently the case with Thunderbird, but that will be resolved after dapper releases).

If you're curious as to how different a package is from Debian, "zless /usr/share/doc/<package>/changelog.Debian.gz" is a good place to look (search for occurances of the string "ubuntu" to see each ubuntu revision, we splice our change entries in where appropriate)

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.