Wednesday, June 24, 2009

Thunderbird 2.0.0.22 – Open Source Email Client

Thunderbird 2.0.0.22 (Windows, Open Source, 6.46MB) [alt DL] is a great email client from the same people who brought you the Firefox browser.

Also available for Linux.

Fixes:

  • Crash viewing multipart/alternative message with text/enhanced part
  • JavaScript chrome privilege escalation
  • Arbitrary code execution using event listeners attached to an element whose owner document is null
  • SSL tampering via non-200 responses to proxy CONNECT requests
    * Crashes with evidence of memory corruption
  • Same-origin violations when Adobe Flash loaded via view-source: scheme
  • Crashes with evidence of memory corruption

0 comments: