-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 04 Oct 2011 20:44:21 +0200 Source: icedove Binary: icedove icedove-dev icedove-dbg Architecture: i386 Version: 3.0.11-1+squeeze5 Distribution: squeeze-security Urgency: high Maintainer: i386 Build Daemon Changed-By: Christoph Goehre Description: icedove - mail/news client with RSS and integrated spam filter support icedove-dbg - Debug Symbols for Icedove icedove-dev - Development files for Icedove Changes: icedove (3.0.11-1+squeeze5) stable-security; urgency=high . * [44577f9] backported patches from xulrunner fixes mfsa2011-{36-40} - MFSA 2011-36 aka CVE-2011-2995: Miscellaneous memory safety hazards (rv:7.0 / rv:1.9.2.23) - MFSA 2011-37 aka CVE-2011-2998: Integer underflow when using JavaScript RegExp - MFSA 2011-38 aka CVE-2011-2999: XSS via plugins and shadowed window.location object - MFSA 2011-39 aka CVE-2011-3000: Defense against multiple Location headers due to CRLF Injection - MFSA 2011-40 aka CVE-2011-2372, CVE-2011-3001: Code installation through holding down Enter Checksums-Sha1: e257d4fc930a20ca390332ccd34cd0f9ed793440 11148370 icedove_3.0.11-1+squeeze5_i386.deb cb84e471df5c2db624d0b122f4f8eff005afd295 5817892 icedove-dev_3.0.11-1+squeeze5_i386.deb bdecea232bd7816d328b3c323920b1998cf96b20 69216852 icedove-dbg_3.0.11-1+squeeze5_i386.deb Checksums-Sha256: 030fd3c2f2e7450b442a94f3758909448c72acaba174cace84a18d435e9e7b82 11148370 icedove_3.0.11-1+squeeze5_i386.deb 98932f5486a24d774c43ba2ea3c6cebc7ddcf61ad44254684f6f466d0649a9fa 5817892 icedove-dev_3.0.11-1+squeeze5_i386.deb 7f3a083a816a38b508681852353e4161f7b7edeeabf60040fd87f9993dde65b6 69216852 icedove-dbg_3.0.11-1+squeeze5_i386.deb Files: cb2549c916770253b0607757b4975c63 11148370 mail optional icedove_3.0.11-1+squeeze5_i386.deb 852da7c1c225e0cc751b81a0f7de347c 5817892 mail optional icedove-dev_3.0.11-1+squeeze5_i386.deb ee4506f0dd3748e44b400dd03f31cf84 69216852 debug extra icedove-dbg_3.0.11-1+squeeze5_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJOi3LHAAoJEGafEd7keGvckCUQAIp9k4mtxQKPJwj7+AaHz18r B/CMZ8CLf7CfeSkW5UMxWhKvsREbTLLTk83d2HNs3NkmEwChvsvmUIurfjUAbxWE COxTu8GbCcOyRs9qnBUz1ZW02rJiwzZkSZdmycpy7SGflDafkFlm0JeBPh8gjkjv Eci7xE+oOHkFWqoGNB2v1UZdQF9ov2+5M5IvLfHXhDohICTAfk57WD1/MASCUkpq JFf5HCdwsNyz6rrXLMVHLAnUCK6Bt4ZhSEMejgLXBXKYB18xTTKVGo7mP10b5gH0 O7nU30MrLPD8ZjWdXVaHoYSqvPSdZr1zHXS/cVirHDDGKPC5gBtmo4OO8AnZXayR 2m2eNvKf6XCt8eaMmpvLnOCucE/a8fK1enpiCY9ZuS0howsm919UHAIytBQ7zh2x HJKfFhpAt/27reu7oE+PS3MWmrVf0KHVfPLoAXmrbNwV7T5sxm0RWpgB5JZWYF8I +gGwr+85KFTQ9yTR1y6Ei+ke+RTb7zVSPSsKSFmQMHZLfKmusYr304QILfRqW0xS 9MYa1JH54ljc541dKzWPoX2hUN3mZDwtWurLqMC7Gf7zAyNDOUfOYqC7snSenceT 5IGJ1YT2NB0xqJhhGF168Y1OC8DBY/AxoyrH8dIHfraeOf5PeSUKU1qy4HP9+0jZ 63z6Ah3IdhMG0AcaYDq/ =ggjz -----END PGP SIGNATURE-----