<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; thunderbird 2.0.0.23</title> <atom:link href="http://www.ghacks.net/tag/thunderbird-2-0-0-23/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 17:32:23 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Email Client Mozilla Thunderbird 2.0.0.23 Update</title><link>http://www.ghacks.net/2009/08/21/email-client-mozilla-thunderbird-2-0-0-23-update/</link> <comments>http://www.ghacks.net/2009/08/21/email-client-mozilla-thunderbird-2-0-0-23-update/#comments</comments> <pubDate>Fri, 21 Aug 2009 17:42:31 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Email]]></category> <category><![CDATA[email client]]></category> <category><![CDATA[mozilla]]></category> <category><![CDATA[mozilla thunderbird]]></category> <category><![CDATA[thunderbird]]></category> <category><![CDATA[thunderbird 2.0.0.23]]></category> <category><![CDATA[thunderbird update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=15588</guid> <description><![CDATA[The Mozilla Thunderbird development team has released an important update for the Mozilla Thunderbird email client. The upgrade which will increase the version of the email client to 2.0.0.23 includes one critical security fix that was reported by security researcher Dan Kaminsky. The compromise of SSL-protected communication vulnerability allows attackers to obtain certificates that would [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/04/mozilla_thunderbird.jpg" alt="mozilla thunderbird" title="mozilla thunderbird" width="156" height="164" class="alignleft size-full wp-image-12014" />The Mozilla Thunderbird development team has released an important update for the Mozilla Thunderbird email client. The upgrade which will increase the version of the email client to 2.0.0.23 includes one critical security fix that was reported by security researcher Dan Kaminsky. The compromise of SSL-protected communication vulnerability allows attackers to obtain certificates that would function for any site they would like to target.</p><p>The email client should pick up the update upon its next startup automatically. Thunderbird users can alternatively use the Help > Check For Updates function in the email client or visit the Mozilla Thunderbird website to <a
href="http://www.mozillamessaging.com/en-US/thunderbird/">obtain</a> the update. The vulnerability, which was disclosed on August 1 is not only affecting the email client but also other Mozilla applications included Mozilla Firefox 3.5 or Firefox 3.0.13.</p><p><span
id="more-15588"></span><br
/><blockquote>IOActive security researcher Dan Kaminsky reported a mismatch in the treatment of domain names in SSL certificates between SSL clients and the Certificate Authorities (CA) which issue server certificates. In particular, if a malicious person requested a certificate for a host name with an invalid null character in it most CAs would issue the certificate if the requester owned the domain specified after the null, while most SSL clients (browsers) ignored that part of the name and used the unvalidated part in front of the null. This made it possible for attackers to obtain certificates that would function for any site they wished to target. These certificates could be used to intercept and potentially alter encrypted communication between the client and a server such as sensitive bank account transactions.</p></blockquote> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/08/21/email-client-mozilla-thunderbird-2-0-0-23-update/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> </channel> </rss>
