[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Security status of mozilla-* packages



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Holger Mense wrote:

> the Mozilla team has recently released new versions of Firefox, Mozilla
> Suite, Thunderbird, which also fix several security issues
> (http://www.mozilla.org/projects/security/known-vulnerabilities.html)
> 
> How far are these issues affected by the Debian packages? Will there be
> a security release for the current packages to fix them?

Actually, the release of Thunderbird which fixes these vulnerabilities
(1.5.0.2) has not completed testing and is not a 'release' yet. The
vulnerability report is confusing, in that it implies that Thunderbird
1.5.0.2 should be available.

I e-mailed Mozilla's security team yesterday and they said that it
should be released shortly (within a day or so).

James
- --
James Davis	+44 1235 822 229	PGP: 0xC7C92EB7
JANET-CERT	0870 850 2340	(+44 1235 822 340)
		Atlas Centre, Chilton, Didcot, Oxfordshire, OX11 0QS
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFER1wsIle3s8fJLrcRApzOAJ4minpCRtuEzsKj9alXASb0KfGhmQCfS5Xl
zn0s4Ro5nKcosiSDcu6+cio=
=erh8
-----END PGP SIGNATURE-----



Reply to: