Secunia CSI7
Advisories
Research
Forums
Create Profile
Our Commitment
PSI
PSI API
CSI
OSI
xSI
Vulnerabilities
Programs
Open Discussions
My Threads
Create Thread
Statistics
About

Forum Thread: Thunderbird 3.1.1 is not last version!

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
Programs

Relating to this vendor:
Mozilla Foundation
And, this specific program:
Mozilla Thunderbird 3.1.x

This thread has been marked as locked.
owilsky Thunderbird 3.1.1 is not last version!
Member 5th Sep, 2010 09:16
Ranking: 0
Posts: 2
User Since: 27th Nov, 2008
System Score: N/A
Location: N/A
Hi,

I am trying the 2.0 beta.
I have German Thunderbird 3.1.1 installed and PSI says that it is patched. But it is not, there is a new 3.1.2 available and that's not a brand new update! I installed 3.1.1 on purpose to check the auto update feature.

Regards,
Oliver

mogs RE: Thunderbird 3.1.1 is not last version!
Expert Contributor 5th Sep, 2010 10:31
Score: 2265
Posts: 6,266
User Since: 22nd Apr 2009
System Score: 100%
Location: UK
Hello.
If you go to "Patch your PC" in the psi2.0 Beta panel; and then Results....is the tick in the box "Auto Updateable" ? And if it is, does Thunderbird appear in the list of progs below ?
Not all programs are included to be auto updated yet.....one reason why it's in Beta.
Hope this helps..........regards,



--
Was this reply relevant?
+1
-0
owilsky RE: Thunderbird 3.1.1 is not last version!
Member 5th Sep, 2010 11:16
Score: 0
Posts: 2
User Since: 27th Nov 2008
System Score: N/A
Location: N/A
Last edited on 5th Sep, 2010 11:17
on 5th Sep, 2010 10:31, mogs wrote:
Hello.
If you go to "Patch your PC" in the psi2.0 Beta panel; and then Results....is the tick in the box "Auto Updateable" ? And if it is, does Thunderbird appear in the list of progs below ?


Yes, it appears (as ) Thunderbird 3.1.x, version detected as 3.1.1.
And yes, Auto Updateable is checked.
Was this reply relevant?
+0
-0
mogs RE: Thunderbird 3.1.1 is not last version!
Expert Contributor 5th Sep, 2010 11:44
Score: 2265
Posts: 6,266
User Since: 22nd Apr 2009
System Score: 100%
Location: UK
Last edited on 5th Sep, 2010 11:46
You'd probably have been better to post this/your observations, in the PSI 2.0 Beta section of the forum ( See in blue on the left ); as a Secunia official would more likely notice it on Monday morning. In fact if you close this thread, by pressing Accept, and post again, it'll likely receive more attention.

This was what I copied from advisory section :-
If you have information about a new or an existing vulnerability in Mozilla Thunderbird 3.1.x then you are more than welcome to contact us.


Table of Contents

1. Product Summary Only



Vendor, Links, and Unpatched Vulnerabilities

Vendor Mozilla Foundation

Product Link View Here (Link to external site)

Affected By 2 Secunia advisories
12 Vulnerabilities

Monitor Product Receive alerts for this product

Unpatched 50% (1 of 2 Secunia advisories)

Most Critical Unpatched
The most severe unpatched Secunia advisory affecting Mozilla Thunderbird 3.1.x, with all vendor patches applied, is rated Highly critical .
http://secunia.com/advisories/product/30717/
I couldn't find anything regarding the newer version 3.2 but noted it was available at site. regards,






--
Was this reply relevant?
+0
-0
Anthony Wells RE: Thunderbird 3.1.1 is not last version!
Expert Contributor 5th Sep, 2010 17:38
Score: 2437
Posts: 3,330
User Since: 19th Dec 2007
System Score: N/A
Location: N/A
Last edited on 5th Sep, 2010 17:44
HI there ,

If you read the first two Secunia Advisories in this list :-

http://secunia.com/advisories/search/?search=Mozil...

You will see that :-

1) 3.1.2 and all prior versions are "insecure" no patch/solution available ,; so all versions are currently "insecure".

2)3.0.6 and 3.1.1 are both the last versions with a security update ; so 3.1.2 is a "bug" fix . The PSI does not record bug and eye candy fixes , so 3.1.1 is the last version recorded as "secure" by Secunia :-

http://www.mozillamessaging.com/en-US/thunderbird/...

MOST IMPORTANT : PLEASE NOTE : In the TP 1.9.0.2 version of the PSI the new "auto-update" facility only installed "international/English language" versions ; I do not know about Beta 2.0 but it does mean that if you have German settings for your Mozilla products , they may get removed/reset in English by "auto-update" . This has happened to a poster with a German Firefox set-up . Firefox may well update to 3.6.9. in the next few days . Unless you can find and confirm otherwise , at this stage , I would disable all programmes with German versions set to auto-update ; rather use the programme's own internal updater .

I hope this is clear , if not , please ask :)

Anthony



--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+5
-0

This thread has been marked as locked.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability