Bug 19490 - Thunderbird 45.4.0
Summary: Thunderbird 45.4.0
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: has_procedure mga5-64-ok mga5-32-ok
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2016-09-29 18:05 CEST by David Walser
Modified: 2016-11-14 19:21 CET (History)
7 users (show)

See Also:
Source RPM: thunderbird
CVE:
Status comment:


Attachments

Description David Walser 2016-09-29 18:05:36 CEST
Thunderbird 45.4.0 is available upstream (the tarball is at least).  It hasn't been announced yet, but we should start preparing the update.  It should fix some subset of the issues fixed in Firefox 45.4:
https://www.mozilla.org/en-US/security/advisories/mfsa2016-86/
Comment 1 magnux77 2016-10-03 16:03:23 CEST
Language packs are still in 45.3.0. So, during update it's causing an error message and update, thunderbird interface is in english.

CC: (none) => magnux77

Comment 2 David Walser 2016-10-03 18:23:50 CEST
magnux77: You shouldn't install packages from updates_testing that have not yet been assigned to QA.  You can check http://madb.mageia.org/tools/updates for a listing of the ones that have been.
Comment 3 David Walser 2016-10-03 18:24:33 CEST
Updated packages uploaded for Mageia 5 and Cauldron by Giuseppe.  Thanks!

Package list below.  Advisory to come later.

Updated packages in core/updates_testing:
================
thunderbird-45.4.0-1.mga5
thunderbird-enigmail-45.4.0-1.mga5
thunderbird-ar-45.4.0-1.mga5
thunderbird-ast-45.4.0-1.mga5
thunderbird-be-45.4.0-1.mga5
thunderbird-bg-45.4.0-1.mga5
thunderbird-bn_BD-45.4.0-1.mga5
thunderbird-br-45.4.0-1.mga5
thunderbird-ca-45.4.0-1.mga5
thunderbird-cs-45.4.0-1.mga5
thunderbird-cy-45.4.0-1.mga5
thunderbird-da-45.4.0-1.mga5
thunderbird-de-45.4.0-1.mga5
thunderbird-el-45.4.0-1.mga5
thunderbird-en_GB-45.4.0-1.mga5
thunderbird-en_US-45.4.0-1.mga5
thunderbird-es_AR-45.4.0-1.mga5
thunderbird-es_ES-45.4.0-1.mga5
thunderbird-et-45.4.0-1.mga5
thunderbird-eu-45.4.0-1.mga5
thunderbird-fi-45.4.0-1.mga5
thunderbird-fr-45.4.0-1.mga5
thunderbird-fy_NL-45.4.0-1.mga5
thunderbird-ga_IE-45.4.0-1.mga5
thunderbird-gd-45.4.0-1.mga5
thunderbird-gl-45.4.0-1.mga5
thunderbird-he-45.4.0-1.mga5
thunderbird-hr-45.4.0-1.mga5
thunderbird-hsb-45.4.0-1.mga5
thunderbird-hu-45.4.0-1.mga5
thunderbird-hy_AM-45.4.0-1.mga5
thunderbird-id-45.4.0-1.mga5
thunderbird-is-45.4.0-1.mga5
thunderbird-it-45.4.0-1.mga5
thunderbird-ja-45.4.0-1.mga5
thunderbird-ko-45.4.0-1.mga5
thunderbird-lt-45.4.0-1.mga5
thunderbird-nb_NO-45.4.0-1.mga5
thunderbird-nl-45.4.0-1.mga5
thunderbird-nn_NO-45.4.0-1.mga5
thunderbird-pa_IN-45.4.0-1.mga5
thunderbird-pl-45.4.0-1.mga5
thunderbird-pt_BR-45.4.0-1.mga5
thunderbird-pt_PT-45.4.0-1.mga5
thunderbird-ro-45.4.0-1.mga5
thunderbird-ru-45.4.0-1.mga5
thunderbird-si-45.4.0-1.mga5
thunderbird-sk-45.4.0-1.mga5
thunderbird-sl-45.4.0-1.mga5
thunderbird-sq-45.4.0-1.mga5
thunderbird-sv_SE-45.4.0-1.mga5
thunderbird-ta_LK-45.4.0-1.mga5
thunderbird-tr-45.4.0-1.mga5
thunderbird-uk-45.4.0-1.mga5
thunderbird-vi-45.4.0-1.mga5
thunderbird-zh_CN-45.4.0-1.mga5
thunderbird-zh_TW-45.4.0-1.mga5

from SRPMS:
thunderbird-45.4.0-1.mga5.src.rpm
thunderbird-l10n-45.4.0-1.mga5.src.rpm

CC: (none) => ghibomgx
Assignee: ghibomgx => qa-bugs

David Walser 2016-10-03 18:24:39 CEST

Version: Cauldron => 5

Comment 4 Bill Wilkinson 2016-10-03 21:39:12 CEST
Tested mga5-64

Send/receive/move/delete under IMAP/SMTP all OK. Calendar entry added and updated as normal. I don't use enigmail, but we seem to be passing without it as it depends on another bug anyway.

CC: (none) => wrw105
Whiteboard: (none) => has_procedure mga5-64-ok

Comment 5 magnux77 2016-10-04 09:30:11 CEST
Xcuze me. It happens to me on Cauldron, not on Mageia 5. But it's the second time the problem occurs on Cauldron.
Comment 6 Rémi Verschelde 2016-10-04 09:38:10 CEST
(In reply to magnux77 from comment #5)
> Xcuze me. It happens to me on Cauldron, not on Mageia 5. But it's the second
> time the problem occurs on Cauldron.

That's normal on Cauldron. thunderbird has to be built first, and thunderbird-l10n only makes sense if the former build succeeded. Since thunderbird takes a long time to build, it's very likely that your mirror will sync in between, and if you run your updates very often, you'll run into a transient issue. Best follow the dev@ mailing list when using cauldron, to be aware of the updates that will land and if you should wait before updating.
Comment 7 David Walser 2016-10-04 17:33:37 CEST
RedHat has issued an advisory for this on October 3:
https://rhn.redhat.com/errata/RHSA-2016-1985.html

Advisory:
================

Updated thunderbird packages fix security vulnerability:

Multiple flaws were found in the processing of malformed web content. A web page
containing malicious content could cause Thunderbird to crash or, potentially,
execute arbitrary code with the privileges of the user running Thunderbird
(CVE-2016-5257).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5257
https://www.mozilla.org/en-US/security/advisories/mfsa2016-86/
https://rhn.redhat.com/errata/RHSA-2016-1985.html

Severity: normal => critical

Comment 8 James Kerr 2016-10-05 16:02:08 CEST
Testing on mga5-64

thunderbird-en_GB-45.4.0-1.mga5.noarch
thunderbird-45.4.0-1.mga5.x86_64        

Packages installed cleanly

Email (POP and SMTP through ISP's server) - OK
Calendar - OK
Unix Movemail - OK
Usenet - OK

This update is OK on mga5-64 for me

CC: (none) => jim

Comment 9 James Kerr 2016-10-05 16:10:15 CEST
Testing on mga5-32

thunderbird-en_GB-45.4.0-1.mga5.noarch
thunderbird-45.4.0-1.mga5.i586 

Packages  installed cleanly

Email - OK
Calendar - 
Unix Movemail - OK

This update is OK for me on mga5-32

Whiteboard: has_procedure mga5-64-ok => has_procedure mga5-64-ok mga5-32-ok

Comment 10 Lewis Smith 2016-10-06 21:33:02 CEST
Validated, Advisory to be uploaded.

Keywords: (none) => validated_update
CC: (none) => lewyssmith, sysadmin-bugs

Comment 11 Mageia Robot 2016-10-06 21:47:45 CEST
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2016-0336.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 12 René Lagoni Neukirch 2016-11-14 16:55:51 CET
I just upgraded TB from the repo - and it doesn't run properly now:

bash-4.3$ thunderbird &
[1] 5461
bash-4.3$ [5461] ###!!! ABORT: JS_SetICUMemoryFunctions failed.: file /home/iurt/rpmbuild/BUILD/thunderbird-45.4.0/thunderbird-45.4.0/mozilla/xpcom/build/XPCOMInit.cpp, line 816
[5461] ###!!! ABORT: JS_SetICUMemoryFunctions failed.: file /home/iurt/rpmbuild/BUILD/thunderbird-45.4.0/thunderbird-45.4.0/mozilla/xpcom/build/XPCOMInit.cpp, line 816

[1]+  Segmentfejl             thunderbird

What could be wrong ?

/René

Status: RESOLVED => REOPENED
CC: (none) => rene
Resolution: FIXED => (none)

Comment 13 David Walser 2016-11-14 19:21:17 CET
Please do not reopen bugs for updates that have been pushed.

Please open a new bug if there's a problem.

Status: REOPENED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.