Mandriva Linux Security Advisory 2009-217 – A number of security vulnerabilities have been discovered in Mozilla Thunderbird. Security issues in thunderbird could lead to a man-in-the-middle attack via a spoofed X.509 certificate. A vulnerability was found in xmltok_impl.c (expat) that with specially crafted XML could be exploited and lead to a denial of service attack.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/80547/MDVSA-2009-217.txt
Source: https://packetstormsecurity.com/files/80547/Mandriva-Linux-Security-Advisory-2009-217.html

