<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="a0979c6fb0b91843c515facb27dd08f8"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="MozillaThunderbird-3546"
    timestamp="1181127029"
    engine="1.0">
  <yum:name>MozillaThunderbird</yum:name>
  <summary lang="en">MozillaThunderbird: Security update to version 1.5.0.12</summary>
  <summary lang="de">MozillaThunderbird: Securityupdate auf Version 1.5.0.12</summary>
  <description lang="en">This update brings Mozilla Thunderbird to security update
version 1.5.0.12.

- MFSA 2007-17 / CVE-2007-2871:

  Chris Thomas demonstrated that XUL popups opened by web
content could be placed outside the boundaries of the
content area. This could be used to spoof or hide parts of
the browser chrome such as the location bar.

- MFSA 2007-16 / CVE-2007-2870:

  Mozilla contributor moz_bug_r_a4 demonstrated that the
addEventListener method could be used to inject script into
another site in violation of the browser's same-origin
policy. This could be used to access or modify private or
valuable information from that other site.

- MFSA 2007-15 / CVE-2007-1558:

  Gaëtan Leurent informed us of a weakness in APOP
authentication that could allow an attacker to recover the
first part of your mail password if the attacker could
interpose a malicious mail server on your network
masquerading as your legitimate mail server. With normal
settings it could take several hours for the attacker to
gather enough data to recover just a few characters of the
password. This result was presented at the Fast Software
Encryption 2007 conference. 

- MFSA 2007-14 / CVE-2007-1362:

  Nicolas Derouet reported two problems with cookie
handling in Mozilla clients. Insufficient length checks
could be use to exhaust browser memory and so to crash the
browser or at least slow it done by a large degree.

  The second issue was that the cookie path and name values
were not checked for the presence of the delimiter used for
internal cookie storage, and if present this confused
future interpretation of the cookie data. This is not
considered to be exploitable.

- MFSA 2007-13 / CVE-2007-2869:

  Marcel reported that a malicious web page could perform a
denial of service attack against the form autocomplete
feature that would persist from session to session until
the malicious form data was deleted. Filling a text field
with millions of characters and submitting the form will
cause the victim's browser to hang for up to several
minutes while the form data is read, and this will happen
the first time autocomplete is triggered after every
browser restart. 

  No harm is done to the user's computer, but the
frustration caused by the hang could prevent use of
Thunderbird if users don't know how to clear the bad state.

- MFSA 2007-12 / CVE-2007-2867 / CVE-2007-2868

  As part of the Thunderbird 2.0.0.4 and 1.5.0.12 update
releases Mozilla developers fixed many bugs to improve the
stability of the product. Some of these crashes that showed
evidence of memory corruption under certain circumstances
and we presume that with enough effort at least some of
these could be exploited to run arbitrary code. 

  Without further investigation we cannot rule out the
possibility that for some of these an attacker might be
able to prepare memory for exploitation through some means
other than JavaScript, such as large images.

- MFSA 2007-11 / CVE-2007-1562:

  Incorrect FTP PASV handling could be used by malicious
ftp servers to do a rudimentary port scanning of for
instance internal networks of the computer the browser is
running on.
</description>
  <description lang="de">Der Mailreader Mozilla Thunderbird wurde auf Version
1.5.0.12 gebracht, die folgende sicherheitsrelevante Fehler
behebt:

- MFSA 2007-17 / CVE-2007-2871:

  Chris Thomas zeigt das von Webinhalten geöffnete XUL
Popups ausserhalb des Web Inhalts angezeigt werden können
und somit zum Spoofen von Browser Elementen verwendet
werden können, wie z.B. der URL Leiste.

- MFSA 2007-16 / CVE-2007-2870:

  Mozilla Kontributor moz_bug_r_a4 demonstrierte das die
addEventListener Methode entgegen der Browser Security
Policy benutzt werden kann Scriptcode in eine andere Seite
einzufügen. Dieses Problem konnte zum Zugriff oder zur
Modifikation von privater und anderer wertvoller
Information benutzt werden.

- MFSA 2007-15 / CVE-2007-1558:

  Gaëtan Leurent hat uns über ein Problem in der APOP
Authentikation informiert, die Angreifern erlaubt den
ersten Teil des Mailpassworts zu entschlüsseln, falls der
Angreifer den legitimen Mailserver durch seinen eigenen
ersetzen kann. Mit normalen Settings dauert das allerdings
mehrere Stunden.

- MFSA 2007-14 / CVE-2007-1362:

  Nicolas Derouet hat zwei Probleme in der Cookie
Behandlung in Mozilla Clients berichtet.  Einerseits können
unzureichende Längen Tests von Angreifern genutzt werden
sehr große Cookie Strings zu allozieren und damit evt den
Browser zum Absturz zu bringen.

  Weiterhin können illegale Zeichen in den Cookie Pfad bzw
Namenswerte eingefügt werden, die auch als Delimiter im
Cookie Storage dienen und somit spätere Auswertung des
Cookies irritieren. Dieses Problem wird aber als nicht
ausnutzbar eingestuft.

- MFSA 2007-13 / CVE-2007-2869:

  Marcel berichtete das eine böse Webseite einen Denial of
Service Angriff gegen das Form Autocompletion Feature
bewirken kann, das über die Sitzung fortdauern kann. Durch
das Füllen des Textfelds mit Millionen von Zeichen und dem
Submitten des Formulars kann dieser Eintrag in den
Komplettierungsspeicher gelangen und beim ersten Ausfüllen
eines beliebigen Formulars den Browser für mehrere Minuten
blockieren.

  Das Problem hier liegt nur in der Frustration des
Benutzers durch das minutenlange Blockieren und der
normalerweise nicht weiss, wie er diesen Zustand behebt.

- MFSA 2007-12 / CVE-2007-2867 / CVE-2007-2868

  Die Mozilla Entwickler haben für die Thunderbird 2.0.0.4
und 1.5.0.12 viele Abstürze behoben und die Stabilität des
Produkts verbessert. Einige dieser Abstürze die Anzeichen
von Memory Corruption zeigen könnten potentiell zum
Ausführen von Schadcode benutzt werden, dies wurde aber
nicht detailliert erforscht.

- MFSA 2007-11 / CVE-2007-1562:

  Inkorrekte FTP PASV Behandlung konnte durch böse FTP
Server dazu benutzt werden ein rudimentäres Port Scanning
im Netz des Rechners des Webbrowsers  durchzuführen.
</description>
  <yum:version ver="3546" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="MozillaThunderbird" epoch="0" ver="1.5.0.12" rel="3.2" flags="EQ"/>
    <rpm:entry kind="atom" name="MozillaThunderbird-translations" epoch="0" ver="1.5.0.12" rel="3.2" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0.12" rel="3.2"/>
      <checksum type="sha" pkgid="YES">1ffe38b6dddfe7e09d98cf2020978cd60d1c0c0c</checksum>
      <time file="1181138622" build="1181127029"/>
      <size package="7922565" installed="24328875" archive="24384216"/>
      <location href="rpm/i586/MozillaThunderbird-1.5.0.12-3.2.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird" epoch="0" ver="1.5.0.12" rel="3.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/MozillaThunderbird-1.5.0.12-3.2.i586.patch.rpm"/>
          <checksum type="sha">3674554a8960867d80ef2d4cbc749d274f879d57</checksum>
          <time file="1181140977" build="1181127029"/>
          <size package="6615559" archive="20770140"/>
          <base-version epoch="0" ver="1.5.0.10" rel="1.1"/>
          <base-version epoch="0" ver="1.5.0.8" rel="3"/>
          <base-version epoch="0" ver="1.5.0.9" rel="0.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/i586/MozillaThunderbird-1.5.0.8_1.5.0.12-3_3.2.i586.delta.rpm"/>
          <checksum type="sha">f2fb1ca7f2888080a814e0ef736342cb89223642</checksum>
          <time file="1181140991" build="1181127029"/>
          <size package="827199" archive="0"/>
          <base-version epoch="0" ver="1.5.0.8" rel="3" md5sum="20d5afbcc012beca4b0c7965b16aa937" buildtime="1164814270" sequence_info="MozillaThunderbird-1.5.0.8-3-7c50472bee81734c79833659967c3e8aaa50"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/i586/MozillaThunderbird-1.5.0.10_1.5.0.12-1.1_3.2.i586.delta.rpm"/>
          <checksum type="sha">b8b7c75c271da29a60c71da679747c249e82fbce</checksum>
          <time file="1181141004" build="1181127029"/>
          <size package="1097923" archive="0"/>
          <base-version epoch="0" ver="1.5.0.10" rel="1.1" md5sum="547473641b1fc691203bef3db6d36c0d" buildtime="1173455125" sequence_info="MozillaThunderbird-1.5.0.10-1.1-ee7aa95483f863f00659bc53596229f862c2111da319239910"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird</name>
      <arch>ppc</arch>
      <version epoch="0" ver="1.5.0.12" rel="3.2"/>
      <checksum type="sha" pkgid="YES">de917859f02a5dc7495dcf0c995318a83626ece0</checksum>
      <time file="1181138679" build="1181129583"/>
      <size package="8036188" installed="27122187" archive="27177528"/>
      <location href="rpm/ppc/MozillaThunderbird-1.5.0.12-3.2.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird" epoch="0" ver="1.5.0.12" rel="3.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/MozillaThunderbird-1.5.0.12-3.2.ppc.patch.rpm"/>
          <checksum type="sha">1d4c96b4cacb9b28616c88de1d73da5f543f88b5</checksum>
          <time file="1181141034" build="1181129583"/>
          <size package="6719029" archive="23452520"/>
          <base-version epoch="0" ver="1.5.0.10" rel="1.1"/>
          <base-version epoch="0" ver="1.5.0.8" rel="3"/>
          <base-version epoch="0" ver="1.5.0.9" rel="0.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/ppc/MozillaThunderbird-1.5.0.8_1.5.0.12-3_3.2.ppc.delta.rpm"/>
          <checksum type="sha">1a401bc4a3cee4709b94357a5828255ceba1e378</checksum>
          <time file="1181141051" build="1181129583"/>
          <size package="748251" archive="0"/>
          <base-version epoch="0" ver="1.5.0.8" rel="3" md5sum="c0c3c4cce8a5a09a31252c696e2354bc" buildtime="1164816306" sequence_info="MozillaThunderbird-1.5.0.8-3-03f74448edb72a70ee32d6a56c6b2f36aa50"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/ppc/MozillaThunderbird-1.5.0.10_1.5.0.12-1.1_3.2.ppc.delta.rpm"/>
          <checksum type="sha">9bbb22f33b01cb0bec8b206ee2385d830d01c630</checksum>
          <time file="1181141067" build="1181129583"/>
          <size package="1058143" archive="0"/>
          <base-version epoch="0" ver="1.5.0.10" rel="1.1" md5sum="5eb4d9bfb70541d73567e314b1221c4e" buildtime="1173452721" sequence_info="MozillaThunderbird-1.5.0.10-1.1-516e48114c19c2a435753b623038845062c2111da319239910"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.5.0.12" rel="3.2"/>
      <checksum type="sha" pkgid="YES">52780f51ad0989a05a4891deaf786b517b5bbbaf</checksum>
      <time file="1181138663" build="1181127852"/>
      <size package="9025837" installed="28216004" archive="28272028"/>
      <location href="rpm/x86_64/MozillaThunderbird-1.5.0.12-3.2.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird" epoch="0" ver="1.5.0.12" rel="3.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/MozillaThunderbird-1.5.0.12-3.2.x86_64.patch.rpm"/>
          <checksum type="sha">64a03e0b9ab48d397037f9467cdf01146f7d260e</checksum>
          <time file="1181141098" build="1181127852"/>
          <size package="7666628" archive="24535740"/>
          <base-version epoch="0" ver="1.5.0.10" rel="1.1"/>
          <base-version epoch="0" ver="1.5.0.8" rel="3"/>
          <base-version epoch="0" ver="1.5.0.9" rel="0.1"/>
        </patchrpm>
        <deltarpm>
          <location href="rpm/x86_64/MozillaThunderbird-1.5.0.8_1.5.0.12-3_3.2.x86_64.delta.rpm"/>
          <checksum type="sha">bab92480e13a2e887bcd137b1a0722978495524b</checksum>
          <time file="1181141118" build="1181127852"/>
          <size package="1390128" archive="0"/>
          <base-version epoch="0" ver="1.5.0.8" rel="3" md5sum="6ab67446150713f480f3392caac9295b" buildtime="1164813862" sequence_info="MozillaThunderbird-1.5.0.8-3-f36677f05a826f91b34aca899ebd5678aa50"/>
        </deltarpm>
        <deltarpm>
          <location href="rpm/x86_64/MozillaThunderbird-1.5.0.10_1.5.0.12-1.1_3.2.x86_64.delta.rpm"/>
          <checksum type="sha">f12fd767301b3e6cdb84f15c5baf70419cf8852d</checksum>
          <time file="1181141135" build="1181127852"/>
          <size package="1349782" archive="0"/>
          <base-version epoch="0" ver="1.5.0.10" rel="1.1" md5sum="571480603ece2894c54437586e5f15ca" buildtime="1173451597" sequence_info="MozillaThunderbird-1.5.0.10-1.1-8eebbe780c9393854ec9d957f2d4ed3a62c2111da319239910"/>
        </deltarpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird-translations</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0.12" rel="3.2"/>
      <checksum type="sha" pkgid="YES">8917e8fc46efab10fbfc5bb7ab4a3ffbe847edb5</checksum>
      <time file="1181138631" build="1181127029"/>
      <size package="4670757" installed="29913309" archive="29924160"/>
      <location href="rpm/i586/MozillaThunderbird-translations-1.5.0.12-3.2.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird-translations" epoch="0" ver="1.5.0.12" rel="3.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/i586/MozillaThunderbird-translations-1.5.0.12-3.2.i586.patch.rpm"/>
          <checksum type="sha">de8338ef57fb5fe1efbff6e209b9c596c2d867c4</checksum>
          <time file="1181141150" build="1181127029"/>
          <size package="16582" archive="124"/>
          <base-version epoch="0" ver="1.5.0.10" rel="1.1"/>
          <base-version epoch="0" ver="1.5.0.8" rel="3"/>
          <base-version epoch="0" ver="1.5.0.9" rel="0.1"/>
        </patchrpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird-translations</name>
      <arch>ppc</arch>
      <version epoch="0" ver="1.5.0.12" rel="3.2"/>
      <checksum type="sha" pkgid="YES">c544bb02c1b55de3ea46540490ddc5db2fc610de</checksum>
      <time file="1181138688" build="1181129583"/>
      <size package="4669005" installed="29913309" archive="29924160"/>
      <location href="rpm/ppc/MozillaThunderbird-translations-1.5.0.12-3.2.ppc.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird-translations" epoch="0" ver="1.5.0.12" rel="3.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/ppc/MozillaThunderbird-translations-1.5.0.12-3.2.ppc.patch.rpm"/>
          <checksum type="sha">c1e18c86137db7254691decadd07e749e8d81133</checksum>
          <time file="1181141196" build="1181129583"/>
          <size package="16566" archive="124"/>
          <base-version epoch="0" ver="1.5.0.10" rel="1.1"/>
          <base-version epoch="0" ver="1.5.0.8" rel="3"/>
          <base-version epoch="0" ver="1.5.0.9" rel="0.1"/>
        </patchrpm>
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>MozillaThunderbird-translations</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.5.0.12" rel="3.2"/>
      <checksum type="sha" pkgid="YES">c0dc6a396f4f43ca34af73f11b82415847b9a6fb</checksum>
      <time file="1181138672" build="1181127852"/>
      <size package="4671187" installed="29913309" archive="29924252"/>
      <location href="rpm/x86_64/MozillaThunderbird-translations-1.5.0.12-3.2.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="MozillaThunderbird-translations" epoch="0" ver="1.5.0.12" rel="3.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="MozillaThunderbird-translations"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
        <patchrpm>
          <location href="rpm/x86_64/MozillaThunderbird-translations-1.5.0.12-3.2.x86_64.patch.rpm"/>
          <checksum type="sha">2ee7a21623de823296dac84ee68e72f38a0f7293</checksum>
          <time file="1181141243" build="1181127852"/>
          <size package="16570" archive="124"/>
          <base-version epoch="0" ver="1.5.0.10" rel="1.1"/>
          <base-version epoch="0" ver="1.5.0.8" rel="3"/>
          <base-version epoch="0" ver="1.5.0.9" rel="0.1"/>
        </patchrpm>
      </pkgfiles>
    </package>
  </atoms>
</patch>
