#7336: thunderbird-38.5.1
-------------------------+-----------------------
Reporter: fo | Owner: fo
Type: enhancement | Status: assigned
Priority: high | Milestone: 7.9
Component: BOOK | Version: SVN
Severity: normal | Resolution:
Keywords: |
-------------------------+-----------------------
Description changed by fo:
Old description:
> [https://ftp.mozilla.org/pub/thunderbird/releases/38.5.1/source/thunderbird-38.5.1.source.tar.bz2]
>
> [https://ftp.mozilla.org/pub/thunderbird/releases/38.5.1/SHA512SUMS]
>
> fed8376375c3ad7df8b773ced7944fb07edbd28e82c907dc6451ad538b8944d6f2a1d5632399f255ab1c7f74a40a9170912fefdbb2fdf423d7dc35108d1baa65
> source/thunderbird-38.5.1.source.tar.bz2
>
> [https://ftp.mozilla.org/pub/thunderbird/releases/38.5.1/SHA512SUMS.asc]
>
> [https://www.mozilla.org/en-US/security/known-
> vulnerabilities/thunderbird/#thunderbird38.5.1]
>
> '''Security Advisories for Thunderbird'''
>
> {{{
> Last was for 38.5.0
> }}}
>
> But on Firefox ESR 38.5:
>
> [https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-
> esr/#firefoxesr38.5.2]
>
> {{{
> Fixed in Firefox ESR 38.5.2
>
> Moderate
> 2015-150 MD5 signatures accepted within TLS 1.2 ServerKeyExchange in
> server signature
> }}}
>
> [https://www.mozilla.org/en-US/thunderbird/38.5.1/releasenotes/]
>
> {{{
> What’s New
>
> Changed
>
> Use a SHA-256 signing certificate for Windows builds, to meet new
> signing requirements
> }}}
New description:
[https://ftp.mozilla.org/pub/thunderbird/releases/38.5.1/source/thunderbird-38.5.1.source.tar.bz2]
[https://ftp.mozilla.org/pub/thunderbird/releases/38.5.1/SHA512SUMS]
2e9be4bcdfe37ad8251365e6b3dfa5be88013a82c56e26723747920bff3c86dd3836165d48a5d09a4185eba842d80c9c659039032d4aa1e72aaffa400c0960b1
source/thunderbird-38.5.1.source.tar.bz2
[https://ftp.mozilla.org/pub/thunderbird/releases/38.5.1/SHA512SUMS.asc]
[https://www.mozilla.org/en-US/security/known-
vulnerabilities/thunderbird/#thunderbird38.5.1]
'''Security Advisories for Thunderbird'''
{{{
Last was for 38.5.0
}}}
But on Firefox ESR 38.5:
[https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-
esr/#firefoxesr38.5.2]
{{{
Fixed in Firefox ESR 38.5.2
Moderate
2015-150 MD5 signatures accepted within TLS 1.2 ServerKeyExchange in
server signature
}}}
[https://www.mozilla.org/en-US/thunderbird/38.5.1/releasenotes/]
{{{
What’s New
Changed
Use a SHA-256 signing certificate for Windows builds, to meet new
signing requirements
}}}
--
--
Ticket URL: <http://wiki.linuxfromscratch.org/blfs/ticket/7336#comment:2>
BLFS Trac <http://wiki.linuxfromscratch.org/blfs>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/listinfo/blfs-book
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page