Thunderbird 2.0.0.22 Fixes Vulnerabilities


Recommended Posts

23 June 2009, 10:22

Thunderbird 2.0.0.22 fixes vulnerabilities

The Mozilla developers have announced the release of Thunderbird 2.0.0.22, fixing several security vulnerabilities in the open source email client. The security and stability update addresses a total of seven security vulnerabilities, most of which were also patched in the recent Firefox 3.0.11 security update.

The update fixes a vulnerability, classified as "high", that could result in an exploitable crash when viewing a multipart/alternative mail message that includes a text/enhanced section. Six vulnerabilities related to JavaScript, four classed as moderate and two as low, that were recently patched in Firefox 3.0.11 have also been addressed in the 2.0.0.22 update. The developers note that vulnerabilities are listed as moderate, rather than critical, for Thunderbird because JavaScript is not enabled by default, as it is in Firefox. Users are strongly discouraged from running JavaScript in mail.

More details about the release can be found in the release notes. Thunderbird 2.0.0.22 is available to download for Windows, Mac OS X and Linux. The developers strongly recommend that all users update to the latest release.

Heise security - http://www.h-online.com/security/Thunderbi...s--/news/113588

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...