Gentoo Security Advisory GLSA 200606-21 (mozilla-thunderbird)

Summary
The remote host is missing updates announced in advisory GLSA 200606-21.
Solution
All Mozilla Thunderbird users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose '>=mail-client/mozilla-thunderbird-1.5.0.4' All Mozilla Thunderbird binary users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose '>=mail-client/mozilla-thunderbird-bin-1.5.0.4' Note: There is no stable fixed version for the Alpha architecture yet. Users of Mozilla Thunderbird on Alpha should consider unmerging it until such a version is available. http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200606-21 http://bugs.gentoo.org/show_bug.cgi?id=135256 http://www.mozilla.org/projects/security/known-vulnerabilities.html#Thunderbird
Insight
Several vulnerabilities in Mozilla Thunderbird allow cross site scripting, JavaScript privilege escalation and possibly execution of arbitrary code.