-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Sat, 27 Mar 2010 12:06:44 +0100 Source: icedove Binary: icedove icedove-gnome-support icedove-dbg icedove-dev Architecture: source i386 Version: 2.0.0.24-0lenny1 Distribution: stable-security Urgency: low Maintainer: Alexander Sack <asac@debian.org> Changed-By: Christoph Goehre <chris@sigxcpu.org> Description: icedove - free/unbranded thunderbird mail/news/rss clone icedove-dbg - Debug Symbols for Icedove icedove-dev - Development files for Icedove icedove-gnome-support - Support for Gnome in Icedove Changes: icedove (2.0.0.24-0lenny1) stable-security; urgency=low . * New upstream security/stability update (v2.0.0.23/v2.0.0.24) * MFSA 2009-42 aka CVE-2009-2408: Compromise of SSL-protected communication * MFSA 2009-43 aka CVE-2009-2404: Heap overflow in certificate regexp parsing * MFSA 2009-49 aka CVE-2009-3077: TreeColumns dangling pointer vulnerability * MFSA 2009-59 aka CVE-2009-0689: Heap buffer overflow in string to number conversion * MFSA 2009-62 aka CVE-2009-3376: Download filename spoofing with RTL override * MFSA 2009-68 aka CVE-2009-3983: NTLM reflection vulnerability * MFSA 2010-07 aka - CVE-2009-2463: Integer overflow in a base64 decoding function - CVE-2009-3072: Crash in the BinHex decoder - CVE-2009-3075: Crash in the JavaScript engine - CVE-2010-0163: Crash indexing some messages with attachments * adjust patches for new upstream - update debian/patches/18_kbsd_nspr.dpatch - update debian/patches/autoconf2.13-rerun - update debian/patches/ubuntu-mail-app-xre-name Checksums-Sha1: d8e1a88c7de17f0562139a9dbc908d88dfb4f9dd 1668 icedove_2.0.0.24-0lenny1.dsc 24c9a3dabc3ee49547784c5d246d9f62713dd641 35856543 icedove_2.0.0.24.orig.tar.gz b6f2cd2d4bfce786df811ac72b7850d673b8381c 103260 icedove_2.0.0.24-0lenny1.diff.gz f1ed4080dc55644a9d6cc01ec8832e31e1ab38c1 10951904 icedove_2.0.0.24-0lenny1_i386.deb 2a8c93ef80af5299837892ad6e7cbfd1fb498377 54838 icedove-gnome-support_2.0.0.24-0lenny1_i386.deb f4025f09004baa3dfd8afbb628203d3ed05142f1 56543048 icedove-dbg_2.0.0.24-0lenny1_i386.deb 46de518ec758b2bd48cc904b8ac20e67d6a331f4 3924810 icedove-dev_2.0.0.24-0lenny1_i386.deb Checksums-Sha256: 5e30a91315ffec8d16a4ef3c1006cbecf0162b60e1090314541e04f1157a3539 1668 icedove_2.0.0.24-0lenny1.dsc 8939873bd9fc2dbabc34ad25516a7358aa7ee82e60c901fba8623521f95ed35e 35856543 icedove_2.0.0.24.orig.tar.gz d61576a1173064639c9d7c87be9ac135c3b73345df2e2981c976bba188654bd2 103260 icedove_2.0.0.24-0lenny1.diff.gz b8ad313762faaeee922d7fd9e7f23331a3614e93759b5744c28c658b1069a63b 10951904 icedove_2.0.0.24-0lenny1_i386.deb 02e1f818045d602375f8c58357e48c6930ddf43520c3dbc91a0971a05b454079 54838 icedove-gnome-support_2.0.0.24-0lenny1_i386.deb 0823fe0c1ce2b82eaef5d6699a0c1a864ab667283f1eb4d24934bbc688b71478 56543048 icedove-dbg_2.0.0.24-0lenny1_i386.deb 562afc87ef1b0066170bcf2125767e47d2575f37ee3c11228c7f5aa7027480a0 3924810 icedove-dev_2.0.0.24-0lenny1_i386.deb Files: 111c1a93c1ce498715e231272123f841 1668 mail optional icedove_2.0.0.24-0lenny1.dsc 3bf6e40cddf593ddc1a66b9e721f12b9 35856543 mail optional icedove_2.0.0.24.orig.tar.gz 4661b0c8c170d58f844337699cb8ca1a 103260 mail optional icedove_2.0.0.24-0lenny1.diff.gz 52ce1587c6eb95b7f8b63ccedf224d88 10951904 mail optional icedove_2.0.0.24-0lenny1_i386.deb 101de9e837bea9391461074481bf770f 54838 mail optional icedove-gnome-support_2.0.0.24-0lenny1_i386.deb 73d1684cf69bed0441393abb46610433 56543048 mail optional icedove-dbg_2.0.0.24-0lenny1_i386.deb 6ecf3693cce2ae97fd0bbdafc1ff06f6 3924810 mail optional icedove-dev_2.0.0.24-0lenny1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkuu888ACgkQ62zWxYk/rQcIQwCfYbCJuZSSPijK0rfAnNuvGEwa WhcAnja/TmTemvMedznsJjGjSOlD1gKl =iOiH -----END PGP SIGNATURE----- Accepted: icedove-dbg_2.0.0.24-0lenny1_i386.deb to main/i/icedove/icedove-dbg_2.0.0.24-0lenny1_i386.deb icedove-dev_2.0.0.24-0lenny1_i386.deb to main/i/icedove/icedove-dev_2.0.0.24-0lenny1_i386.deb icedove-gnome-support_2.0.0.24-0lenny1_i386.deb to main/i/icedove/icedove-gnome-support_2.0.0.24-0lenny1_i386.deb icedove_2.0.0.24-0lenny1.diff.gz to main/i/icedove/icedove_2.0.0.24-0lenny1.diff.gz icedove_2.0.0.24-0lenny1.dsc to main/i/icedove/icedove_2.0.0.24-0lenny1.dsc icedove_2.0.0.24-0lenny1_i386.deb to main/i/icedove/icedove_2.0.0.24-0lenny1_i386.deb icedove_2.0.0.24.orig.tar.gz to main/i/icedove/icedove_2.0.0.24.orig.tar.gz