Subject: CVS commit: [pkgsrc-2006Q1] pkgsrc/mail
To: None <pkgsrc-changes@NetBSD.org>
From: Lubomir Sedlacik <salo@netbsd.org>
List: pkgsrc-changes
Date: 04/23/2006 23:11:55
Module Name: pkgsrc
Committed By: salo
Date: Sun Apr 23 23:11:55 UTC 2006
Modified Files:
pkgsrc/mail/thunderbird [pkgsrc-2006Q1]: Makefile
Makefile-thunderbird.common distinfo
pkgsrc/mail/thunderbird-gtk1 [pkgsrc-2006Q1]: Makefile
pkgsrc/mail/thunderbird/patches [pkgsrc-2006Q1]: patch-ab
Log Message:
Pullup ticket 1442 - requested by ghen
security update for thunderbird
Revisions pulled up:
- pkgsrc/mail/thunderbird/Makefile 1.18
- pkgsrc/mail/thunderbird/Makefile-thunderbird.common 1.12
- pkgsrc/mail/thunderbird/distinfo 1.22
- pkgsrc/mail/thunderbird/patches/patch-ab 1.9
- pkgsrc/mail/thunderbird-gtk1/Makefile 1.9
Module Name: pkgsrc
Committed By: ghen
Date: Sun Apr 23 14:14:07 UTC 2006
Modified Files:
pkgsrc/mail/thunderbird: Makefile Makefile-thunderbird.common
distinfo
pkgsrc/mail/thunderbird-gtk1: Makefile
pkgsrc/mail/thunderbird/patches: patch-ab
Log Message:
Update to Thunderbird 1.5.0.2 (1.5.0.1 was skipped to stay in sync with
Firefox).
Thunderbird 1.5.0.2 offers improved stability, and several security fixes:
MFSA 2006-28 Security check of js_ValueToFunctionObject() can be
circumvented
MFSA 2006-27 Table Rebuilding Code Execution Vulnerability
MFSA 2006-26 Mail Multiple Information Disclosure
MFSA 2006-25 Privilege escalation through Print Preview
MFSA 2006-24 Privilege escalation using crypto.generateCRMFRequest
MFSA 2006-22 CSS Letter-Spacing Heap Overflow Vulnerability
MFSA 2006-21 JavaScript execution in mail when forwarding in-line
MFSA 2006-20 Crashes with evidence of memory corruption (rv:1.8.0.2)
MFSA 2006-08 "AnyName" entrainment and access control hazard
MFSA 2006-07 Read beyond buffer while parsing XML
MFSA 2006-06 Integer overflows in E4X, SVG and Canvas
MFSA 2006-05 Localstore.rdf XML injection through XULDocument.persist()
MFSA 2006-04 Memory corruption via QueryInterface on Location, Navigator
objects
MFSA 2006-02 Changing postion:relative to static corrupts memory
MFSA 2006-01 JavaScript garbage-collection hazards
For a detailed ChangeLog, see:
http://weblogs.mozillazine.org/rumblingedge/archives/2006/02/1-5-0-2.html
To generate a diff of this commit:
cvs rdiff -r1.17 -r1.17.2.1 pkgsrc/mail/thunderbird/Makefile
cvs rdiff -r1.11 -r1.11.2.1 \
pkgsrc/mail/thunderbird/Makefile-thunderbird.common
cvs rdiff -r1.21 -r1.21.2.1 pkgsrc/mail/thunderbird/distinfo
cvs rdiff -r1.8 -r1.8.2.1 pkgsrc/mail/thunderbird-gtk1/Makefile
cvs rdiff -r1.8 -r1.8.2.1 pkgsrc/mail/thunderbird/patches/patch-ab
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.