Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 218065
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Hanno Boeck <hanno@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 218065 depends on: 230567 Show dependency tree
Bug 218065 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-04-17 08:47 0000
Cite advisory from mozilla.org:
"Fixes for security problems in the JavaScript engine described in MFSA 2008-15
(CVE-2008-1237) introduced a stability problem, where some users experienced
crashes during JavaScript garbage collection. This is being fixed primarily to
address stability concerns. We have no demonstration that this particular crash
is exploitable but are issuing this advisory because some crashes of this type
have been shown to be exploitable in the past."

------- Comment #1 From Raúl Porcel 2008-04-17 12:25:29 0000 -------
=www-client/mozilla-firefox[-bin]-2.0.0.14
=net-libs/xulrunner-1.8.1.14

In the tree

seamonkey-1.1.10 is not released yet, and thunderbird either

------- Comment #2 From Robert Buchholz 2008-04-18 00:06:37 0000 -------
Arches, please test and mark stable:
=www-client/mozilla-firefox-2.0.0.14
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 release sparc x86"

=www-client/mozilla-firefox-bin-2.0.0.14
Target keywords : "amd64 release x86"

=net-libs/xulrunner-1.8.1.14
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 release sparc x86"

------- Comment #3 From Jeroen Roovers 2008-04-18 03:04:18 0000 -------
Both stable for HPPA. Probably need to stay on board for seamonkey (if not
please tell).

------- Comment #4 From Raúl Porcel 2008-04-18 10:59:01 0000 -------
alpha/ia64/sparc/x86 stable

------- Comment #5 From Markus Meier 2008-04-19 13:51:28 0000 -------
amd64 stable

------- Comment #6 From Markus Rothe 2008-04-19 15:42:00 0000 -------
ppc64 stable

------- Comment #7 From Jeroen Roovers 2008-04-21 16:13:46 0000 -------
No seamonkey-1.1.10 yet?

------- Comment #8 From Tobias Scherbaum 2008-04-22 16:12:59 0000 -------
ppc stable, ready for glsa.

------- Comment #9 From Peter Volkov 2008-04-23 20:25:26 0000 -------
Fixed in release snapshot.

------- Comment #10 From Robert Buchholz 2008-05-17 11:49:01 0000 -------
According to this blog entry, Seamonkey upstream has decided not to release
1.1.10 anytime soon:
http://home.kairo.at/blog/2008-04/weekly_status_report_w17_2008_w15_w16

Raul has committed the patch to fix this vulnerability in
www-client/seamonkey-1.1.9-r1. There are no updates to www-client/seamonkey-bin
due to the nature of being upstream builds.

------- Comment #11 From Robert Buchholz 2008-05-17 11:49:29 0000 -------
Arches, please test and mark stable:
=www-client/seamonkey-1.1.9-r1
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 release sparc x86"

------- Comment #12 From Raúl Porcel 2008-05-17 19:11:04 0000 -------
alpha/ia64/sparc stable

------- Comment #13 From Christian Faulhammer 2008-05-18 08:26:18 0000 -------
x86 stable

------- Comment #14 From Markus Rothe 2008-05-18 14:29:48 0000 -------
ppc64 stable

------- Comment #15 From Robert Buchholz 2008-05-18 15:34:25 0000 -------
amd64 stable

------- Comment #16 From Jeroen Roovers 2008-05-18 15:56:40 0000 -------
Stable for HPPA.

------- Comment #17 From Tobias Scherbaum 2008-05-20 16:32:50 0000 -------
ppc stable

------- Comment #18 From Robert Buchholz 2008-05-20 21:22:10 0000 -------
GLSA 200805-18, but we will have to leave this open until it is fixed for
seamonkey-bin.

------- Comment #19 From Peter Volkov 2008-05-21 09:36:58 0000 -------
Fixed in release snapshot.

------- Comment #20 From Robert Buchholz 2008-07-30 19:53:46 0000 -------
Fixed via bug 230567

------- Comment #21 From Robert Buchholz 2008-08-06 00:43:23 0000 -------
GLSA 200808-03

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug