Secunia CSI7
Advisories
Research
Forums
Create Profile
Our Commitment
PSI
PSI API
CSI
OSI
xSI
Vulnerabilities
Programs
Open Discussions
My Threads
Create Thread
Statistics
About

Forum Thread: Thunderbird 16.x while TB 17.0 is long out

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
Programs

Relating to this vendor:
Mozilla Foundation
And, this specific program:
Mozilla Thunderbird 16.x

This thread has been marked as locked.
Krischu Thunderbird 16.x while TB 17.0 is long out
Member 26th Nov, 2012 18:36
Ranking: 0
Posts: 27
User Since: 30th Jul, 2010
System Score: 96%
Location: DE
Last edited on 26th Nov, 2012 18:50

Today PSI 2.0 claims to update Thunderbird 16.x while I have 17.0 long installed.
And it overwrote my 17.0 installation (German) with an English one
although I specified the language in PSI.

--
Christoph

E.Jeppesen RE: Thunderbird 16.x while TB 17.0 is long out
Secunia Official 27th Nov, 2012 10:38
Score: 220
Posts: 618
User Since: 24th Nov 2008
System Score: N/A
Location: Copenhagen, DK
It sounds like you have some old files left from the previous installation of Thunderbird. However, we have just updated our detection rules for Thunderbird. Please try a rescan and see if that has fixed the detection issue.

As for installing the incorrect language version, if you let me know which version of Windows you are using and also your PSI version, I will attempt to recreate the issue.
Krischu RE: Thunderbird 16.x while TB 17.0 is long out
Member 27th Nov, 2012 10:49
Score: 0
Posts: 27
User Since: 30th Jul 2010
System Score: 96%
Location: DE
Last edited on 27th Nov, 2012 10:57
I clicked to ignore that product. I found that I had a directory c:\programme (x86)\Mozilla Thunderbird.bak which had the old .exe in it.

Probably my fault, that I did that rename or do Thunderbird update do such renaming?
Believe not.

--
Christoph

P.S. It is PSI 3.0 to be precise.
Was this reply relevant?
+0
-0
E.Jeppesen RE: Thunderbird 16.x while TB 17.0 is long out
Secunia Official 27th Nov, 2012 12:02
Score: 220
Posts: 618
User Since: 24th Nov 2008
System Score: N/A
Location: Copenhagen, DK
I am not sure if the Thunderbird installer could have renamed your folders. What you can do, if you can locate an old thunderbird.exe file it to open it and use its build-in update mechanism. That should update that exact instance of Thunderbird.

Please also see this FAQ entry to examine the file detected by the PSI.
http://secunia.com/vulnerability_scanning/personal...

Anthony Wells RE: Thunderbird 16.x while TB 17.0 is long out
Expert Contributor 27th Nov, 2012 15:39
Score: 2428
Posts: 3,316
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

Hi ,

A similar type of problem occured here a few weeks ago :-

http://secunia.com/community/forum/thread/show/133...

There is a general problem of the PSI "auto-update" seeing a non-default location programme version and instaling or reinstalling the latest version in/over the existing default installation .

I also hope that support are ready (as advised some time ago) to differentiate between the Mozilla software "release" channel and the "ESR" channel which are supposed to split around now on the 17 platform , as it previously did with platform 10 and caused problems at that time ..

Take care

Anthony

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+0
-0
E.Jeppesen RE: Thunderbird 16.x while TB 17.0 is long out
Secunia Official 27th Nov, 2012 16:04
Score: 220
Posts: 618
User Since: 24th Nov 2008
System Score: N/A
Location: Copenhagen, DK
These versions of Mozilla Firefox are currently considered as patched:
17.x
10.0.11esr

So yes, we do distinguish between the ESR (Extended Support Release) and the primary Firefox release versions.
Anthony Wells RE: Thunderbird 16.x while TB 17.0 is long out
Expert Contributor 28th Nov, 2012 17:24
Score: 2428
Posts: 3,316
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

Hello Emil ,

The detection between version 10.0.x ESR and 11.0.x (->17.0x) was initially difficult abd resulted in a certain compromise at the outset ; it is now resolved as you state .

My point concerns the next proposed (about now) jump and re-split by the ESR channel previewed here :-

http://www.mozilla.org/en-US/firefox/organizations...

My question was is whether the new rules will (as suggested at the time) be able to detect the difference when same Platform version is applied to the Mozilla software "Release" and "ESR" channels ?? This was not possible before .

Take care

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+0
-0
E.Jeppesen RE: Thunderbird 16.x while TB 17.0 is long out
Secunia Official 29th Nov, 2012 12:20
Score: 220
Posts: 618
User Since: 24th Nov 2008
System Score: N/A
Location: Copenhagen, DK
@Anthony
We’ll certainly do our best to distinguish between the Firefox versions you have mentioned. I don’t expect this to be an issue but we may as previously need to adjust our detections rules. Please make sure to send us a software suggestion for the new ESR version of Firefox if you see any detection issues.
Anthony Wells RE: Thunderbird 16.x while TB 17.0 is long out
Expert Contributor 30th Nov, 2012 17:14
Score: 2428
Posts: 3,316
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

Hi Emil ,

I am on the release channel , however @wr is on the ESR channel and so i/we can try to coordinate with him in due course . I have asked him to look at this thread .

Take care

Anthony

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+0
-0
wr RE: Thunderbird 16.x while TB 17.0 is long out
Contributor 30th Nov, 2012 20:45
Score: 308
Posts: 736
User Since: 30th Mar 2008
System Score: 100%
Location: US
Hi all

@ Anthony-I just completed a full
system scan to be sure detection of my ESR
version of Ff was correctly detected & displayed.
No problem there-v10.0.11.4702 correctly
detected.
I will keep a close eye on this matter as
time is close for another 'split'-thanks for your
input & jogging my memory.

Hope all is well with you-gotta go-'tis the season.

Regards, wr

--
HP Pavilion Slimline s3020n
Windows Vista Home Premium SP2 32 bit
AMD 64 Athlon X2
Firefox 24.4.0 ESR
The weakest link of a computer system is always sitting in front of the monitor.
Was this reply relevant?
+0
-0
pmmgpgp RE: Thunderbird 16.x while TB 17.0 is long out
Member 1st Dec, 2012 16:46
Score: 0
Posts: 2
User Since: 25th May 2012
System Score: N/A
Location: N/A
I have a VISTA PC with Windows Vista Home Premium Service Pack 2 (build 6002).

As reported by Belarc Advisor:
I am current with PSI
Secunia PSI Agent Version 3.0.0.4001
Secunia PSI Tray Version 3.0.0.4001
Secunia PSI Version 3.0.0.4001
Secunia Update Agent Version 3.0.0.4001

As reported by Belarc Advisor:
I am also current with Mozilla
Mozilla Corporation - Firefox Version 17.0
Mozilla Corporation - Thunderbird Version 17.0
Mozilla Foundation - Firefox Version 17.0

+++++++++++++++++++

PSI thinks that my Thunderbird is out of date
Mozilla Thunderbird 16.x
Was this reply relevant?
+0
-0
Maurice Joyce RE: Thunderbird 16.x while TB 17.0 is long out
Handling Contributor 1st Dec, 2012 17:04
Score: 11610
Posts: 8,906
User Since: 4th Jan 2009
System Score: N/A
Location: UK
What path is PSI showing to the vulnerability?

FINDING A FILE PATH USING PSI

VERSION 2


From the DASHBOARD page click on SCAN RESULTS.

1. This will list all your programmes with a + to the left of each programme.
2. Click the + sign next to the item that U want help with.
3. This will reveal the path under DETECTED INSTANCES.
4. Below DETECTED INSTANCES you will see this You can double click this row for additional information & options>double click it>a box will appear>look to the RIGHT & U will see TROUBLESHOOT REPORT in BLUE writing under the heading TOOLBOX> click TroubleShoot Report & it will reveal some information in a box>highlight the information revealed from ---START--- to ---END--- & copy it (CTRL+C) then post it to the Forum (CTRL+V)

VERSION 3
This version does not have such an easy method to publish the path.

Open PSI>once open select Show Programs.
U will now see a page full of programme icons or a list.
Right click on the programme in error>select Show Details - that will open a box showing the path & version number of the offending file.
U now have 2 options:
1. Write down the exact file path & install version - return to the Forum & type that information.
2. Take a screen shot & publish that.

Last Reviewed 20:17 22/10/2012

--
Maurice

Windows 7 SP1 64 Bit OS
HP Intel Pentium i7
IE 11 for Windows 7 SP1
16GB RAM
Was this reply relevant?
+1
-0
pmmgpgp RE: Thunderbird 16.x while TB 17.0 is long out
Member 1st Dec, 2012 17:20
Score: 0
Posts: 2
User Since: 25th May 2012
System Score: N/A
Location: N/A
That "solved it".

I while back had I had to re-install Thunderbird.

To avoid and possible loss of data I had renamed the folder to "Mozilla Thunderbird-old" (not delete it); PSI still found it.

I renamed thunderbird.exe to thunderbird.ex_ and resolved the issue.

Thank you for the prompt and detailed reply.

Dave
Was this reply relevant?
+0
-0

This thread has been marked as locked.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability