<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; thunderbird security</title> <atom:link href="http://www.ghacks.net/tag/thunderbird-security/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 07:07:56 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Mozilla Thunderbird 3.1.10 Released</title><link>http://www.ghacks.net/2011/04/28/mozilla-thunderbird-3-1-10-released/</link> <comments>http://www.ghacks.net/2011/04/28/mozilla-thunderbird-3-1-10-released/#comments</comments> <pubDate>Thu, 28 Apr 2011 17:37:17 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Email]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[email client]]></category> <category><![CDATA[mozilla thunderbird]]></category> <category><![CDATA[thunderbird]]></category> <category><![CDATA[thunderbird security]]></category> <category><![CDATA[thunderbird update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=44489</guid> <description><![CDATA[Big release day at Mozilla. Mozilla Thunderbird 3.1.10 has been released next to Firefox 4.0.1 on the very same day. The release notes of the new version of the email client mention several performance, stability and security fixes without going into greater detail. The linked Security Advisory page does not list the changes in that [...]]]></description> <content:encoded><![CDATA[<p>Big release day at Mozilla. Mozilla Thunderbird 3.1.10 has been released next to <a
href="http://www.ghacks.net/2011/04/28/firefox-4-0-1-has-been-released/">Firefox 4.0.1</a> on the very same day. The release notes of the new version of the email client mention several performance, stability and security fixes without going into greater detail. The linked Security Advisory page does not list the changes in that new release yet, which leaves Bugzilla as the only source of information.</p><p>Bugzilla lists a total of 71 bugs that have been fixed in Mozilla Thunderbird 3.1.10, of which two have received the highest possible rating blocker. Additionally, 16 of the issues listed have received a severity rating of critical, and another four one of major.</p><p>Several of the fixes appear to be language related, for instance crash fixes when spell checking with French or Hungarian dictionaries, or update crashes when localized strings excess certain parameters.</p><p>Just check <a
href="https://bugzilla.mozilla.org/buglist.cgi?field0-0-0=cf_status_thunderbird31;type0-0-1=equals;field0-0-1=cf_status_192;query_format=advanced;value0-0-1=.17-fixed;type0-0-0=equals;value0-0-0=.10-fixed;type0-0-2=equals;field0-0-2=cf_status_192;value0-0-2=.16-fixed">Bugzilla</a> for the full list of fixes in this version of Thunderbird. The release, unlike that of Firefox 4.0.1 is already available for download at the official Mozilla Messaging website.</p><p>You can for instance download it <a
href="http://www.mozillamessaging.com/en-US/thunderbird/3.1.10/releasenotes/">from the</a> official release notes page. It is likely that the email client will pick up the new release soon as well and display notifications in the application, so that in-application updates will become possible as well.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/04/28/mozilla-thunderbird-3-1-10-released/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Thunderbird 3 JavaScript, What&#8217;s The Deal?</title><link>http://www.ghacks.net/2010/06/30/thunderbird-3-javascript-whats-the-deal/</link> <comments>http://www.ghacks.net/2010/06/30/thunderbird-3-javascript-whats-the-deal/#comments</comments> <pubDate>Wed, 30 Jun 2010 14:50:12 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Email]]></category> <category><![CDATA[javascript]]></category> <category><![CDATA[mozilla thundebird]]></category> <category><![CDATA[thunderbird]]></category> <category><![CDATA[thunderbird javascript]]></category> <category><![CDATA[thunderbird security]]></category> <category><![CDATA[thunderbird tips]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=27684</guid> <description><![CDATA[Veteran users of the Thunderbird email client might remember that JavaScript was supported in version 2. Users who have recently upgraded to version 3 of Thunderbird might also have noted that JavaScript is no longer executed by the software, at least in email contexts. So what&#8217;s the deal with JavaScript and Thunderbird? The Thunderbird developers [...]]]></description> <content:encoded><![CDATA[<p>Veteran users of the Thunderbird email client might remember that JavaScript was supported in version 2. Users who have recently upgraded to version 3 of Thunderbird might also have noted that JavaScript is no longer executed by the software, at least in email contexts.</p><p>So what&#8217;s the deal with JavaScript and Thunderbird? The Thunderbird developers have apparently <a
href="https://developer.mozilla.org/En/Thunderbird_3_for_developers">decided</a> to remove JavaScript support in Thunderbird 3.</p><blockquote><p>Due to various security considerations. Javascript has been disabled completely in message content (the javascript.allow.mailnews preference no longer has any effect). Javascript is enabled for remote content including RSS feeds.</p></blockquote><p><span
id="more-27684"></span>JavaScript is still available for RSS feeds but not in message content. To begin with, this change likely affects only a minority of Thunderbird users, with most probably not even knowing that JavaScript was enabled at a time in the email client.</p><p>The definite answer at this point is that the developer&#8217;s have no intention of adding JavaScript again to the program. There is currently no config option or add-on that will bring back JavaScript in Thunderbird 3.</p><p>Thunderbird 3 users who read RSS feeds in the application might want to consider disabling JavaScript in this context as well to improve the security of the client. JavaScript is usually not needed to read RSS feeds although some media feeds might require it.</p><p>Here is how this is done:</p><p>Open the Tools > Options menu in Thunderbird. Switch to the Advanced tab and click the Config Editor button in the General sub-tab.</p><div
id="attachment_27686" class="wp-caption alignnone" style="width: 510px"><img
src="http://www.ghacks.net/wp-content/uploads/2010/06/thunderbird-3-options-500x416.png" alt="thunderbird 3 options" title="thunderbird 3 options" width="500" height="416" class="size-medium wp-image-27686" /><p
class="wp-caption-text">thunderbird 3 options</p></div><p>Confirm to be careful if this menu is opened for the first time. Enter JavaScript in the filter and locate the parameter JavaScript.enabled. Double-click that parameter to set it to false.</p><div
id="attachment_27687" class="wp-caption alignnone" style="width: 510px"><img
src="http://www.ghacks.net/wp-content/uploads/2010/06/thunderbird-javascript-500x152.png" alt="thunderbird javascript" title="thunderbird javascript" width="500" height="152" class="size-medium wp-image-27687" /><p
class="wp-caption-text">thunderbird javascript</p></div><p>This disables JavaScript for RSS feeds in Thunderbird 3. Scripts that are included are ignored by Thunderbird. It is not clear if a restart is required, it is recommended to restart to make sure the new setting is recognized by Thunderbird.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/06/30/thunderbird-3-javascript-whats-the-deal/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Thunderbird Security Update To 2.0.0.17</title><link>http://www.ghacks.net/2008/09/26/thunderbird-security-update-to-20017/</link> <comments>http://www.ghacks.net/2008/09/26/thunderbird-security-update-to-20017/#comments</comments> <pubDate>Fri, 26 Sep 2008 07:08:47 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Email]]></category> <category><![CDATA[email client]]></category> <category><![CDATA[mozilla]]></category> <category><![CDATA[thunderbird]]></category> <category><![CDATA[thunderbird security]]></category> <category><![CDATA[thunderbird update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=7232</guid> <description><![CDATA[Just a day after updating both Firefox version 3 and 2 the Mozilla Thunderbird development team released a update for Thunderbird which raises the version of the email client to 2.0.0.17. The update is a security update and it is therefor recommended to update immediately if Thunderbird is installed and in use on a computer [...]]]></description> <content:encoded><![CDATA[<p>Just a day after updating both Firefox version 3 and 2 the Mozilla Thunderbird development team released a update for Thunderbird which raises the version of the email client to 2.0.0.17.</p><p>The update is a security update and it is therefor recommended to update immediately if Thunderbird is installed and in use on a computer system.</p><p>Interested users can take a <a
href="http://www.mozillamessaging.com/en-US/thunderbird/2.0.0.17/releasenotes/">look</a> at the release notes for the new version which contain a link to the security issues that have been fixed.</p><p>The update fixes the following two critical and five moderate security vulnerabilities that can be exploited in earlier versions of the mail client:</p><p><span
id="more-7232"></span><ul><li>MFSA 2008-46  Heap overflow when canceling newsgroup message</li><li>MFSA 2008-44 resource: traversal vulnerabilities</li><li>MFSA 2008-43 BOM characters stripped from JavaScript before execution</li><li>MFSA 2008-42 Crashes with evidence of memory corruption (rv:1.9.0.2/1.8.1.17)</li><li>MFSA 2008-41 Privilege escalation via XPCnativeWrapper pollution</li><li>MFSA 2008-38 nsXMLDocument::OnChannelRedirect() same-origin violation</li><li>MFSA 2008-37 UTF-8 URL stack buffer overflow</li></ul><p>The update checks in the email client can be used to download the latest version. Users find that option in the Help > Check for Updates menu in Thunderbird. Everyone else can use the link posted above to download the email client Thunderbird from the official Mozilla website.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/09/26/thunderbird-security-update-to-20017/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Thunderbird 2.0.0.6 is out</title><link>http://www.ghacks.net/2007/08/02/thunderbird-2006-is-out/</link> <comments>http://www.ghacks.net/2007/08/02/thunderbird-2006-is-out/#comments</comments> <pubDate>Thu, 02 Aug 2007 06:08:50 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Email]]></category> <category><![CDATA[thunderbird 2.0.0.6]]></category> <category><![CDATA[thunderbird security]]></category> <category><![CDATA[thunderbird update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2007/08/02/thunderbird-2006-is-out/</guid> <description><![CDATA[After releasing the Firefox update to 2.0.0.6 early because of a serious security vulnerability the update for Thunderbird was released on schedule. The automatic update routine is already suggesting to update Thunderbird to its newest version and the website has been updated with the latest information as well.]]></description> <content:encoded><![CDATA[<p>After releasing the Firefox update to 2.0.0.6 early because of a serious security vulnerability the update for Thunderbird was released on schedule. The automatic update routine is already suggesting to update Thunderbird to its newest version and the <a
href="http://www.mozillamessaging.com/en-US/thunderbird/">website</a> has been updated with the latest information as well.</p><p>The same security vulnerabilities that have been fixed in Firefox 2.0.0.6 have also been fixed in Thunderbird which means that you should update immediately to the latest version. As far as I can tell there are no new features in this version, at least all my extensions are still working fine.</p><p>The Rumbling Edge lists the following three <a
href="http://weblogs.mozillazine.org/rumblingedge/archives/2007/08/tb_2-0-0-6.html">fixes</a> for Thunderbird 2.0.0.6</p><p>Fixed: MFSA 2007-27 &#8211; Unescaped URIs passed to external programs (Critical)<br
/> Fixed: MFSA 2007-26 &#8211; Privilege escalation through chrome-loaded about:blank windows (Moderate)<br
/> Fixed: 389106 &#8211; firefox may not escape quotes everywhere</p><p><span
id="more-1822"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2007/08/02/thunderbird-2006-is-out/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
