Monday, July 28, 2008

Mozilla Thunderbird 2.0.0.16 - Open Source Email Client

Mozilla Thunderbird 2.0.0.16 (Windows, Open Source, 6.6MB) [alternate download] is a redesign of the Mozilla mail component. The goal is to produce a cross platform stand alone mail application using the XUL user interface language.

Also available for Linux.

Changes:

  • Fixed security issues:
    • Remote code execution by overflowing CSS reference counter
    • Crash and remote code execution in block reflow
    • Peer-trusted certs can use alt names to spoof
    • Faulty .properties file results in uninitialized memory being used
    • Buffer length checks in MIME processing
    • Arbitrary code execution in mozIJSSubScriptLoader.loadSubScript()
    • Chrome script loading from fastload file
    • Crashes with evidence of memory corruption (rv:1.8.1.15)

0 comments: