<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>165555</bug_id>
          
          <creation_ts>2007-02-06 03:01 0000</creation_ts>
          <short_desc>www-client/(mozilla-firefox|seamonkey)-(bin)?,mail-client/thunderbird(-bin)?,dev-libs/nss: Security release (CVE-2006-6077,2007-000[89],077[5-9],0780,080[01],0981,0995,1004,1092)</short_desc>
          <delta_ts>2007-06-24 23:56:12 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.securiteam.com/securitynews/5JP051FKKE.html</bug_file_loc>
          <status_whiteboard>A2 [glsa] Falco</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>keith@email.arizona.edu</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>mips@gentoo.org</cc>
    
    <cc>mozilla@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>keith@email.arizona.edu</who>
            <bug_when>2007-02-06 03:01:12 0000</bug_when>
            <thetext>There is an interesting vulnerability in the default behavior of Firefox built-in popup blocker. This vulnerability, coupled with an additional trick, allows the attacker to read arbitrary user-accessible files on the system, and thus steal some fairly sensitive information.

Reproducible: Didn&apos;t try




http://www.securiteam.com/securitynews/5JP051FKKE.html</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-10 22:09:38 0000</bug_when>
            <thetext>Thanks. AFAIK, there is no upstream fixed version yet.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-23 15:49:48 0000</bug_when>
            <thetext>*** Bug 166945 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-23 20:06:35 0000</bug_when>
            <thetext>http://www.mozilla.org/security/announce/

As usual, the CVE and vulnerable packages on the mozilla site are not exact and a little work must be done to sort the vulns.

The following packages have just been released and fixes the vulnerabilities

Firefox 2.0.0.2
Firefox 1.5.0.10
SeaMonkey 1.0.8
Thunderbird 1.5.0.10
NSS 3.11.5

CVE-2006-6077 mfsa2007-02 FF SM
CVE-2007-0008 mfsa2007-06(FF SM TB)NSS
CVE-2007-0009 mfsa2007-06(FF SM TB)NSS
CVE-2007-0775 mfsa2007-01 FF SM TB
CVE-2007-0776 mfsa2007-01 FF SM TB
CVE-2007-0777 mfsa2007-01 FF SM TB
CVE-2007-0778 mfsa2007-03 FF SM
CVE-2007-0779 mfsa2007-04 FF SM
CVE-2007-0780 mfsa2007-05 FF SM
CVE-2007-0800 mfsa2007-05 FF SM
CVE-2007-0801 mfsa2007-05 FF SM
CVE-2007-0981 mfsa2007-07 FF SM
CVE-2007-0995 mfsa2007-02 FF SM

You can note that CVE-2007-0801 is not covered by the mozilla announcement whereas it is fixed in mfsa2007-05 according to its text. Similarly, mfsa2007-06.html doesn&apos;t mention Thunderbird as vulnerable whereas it is.

I don&apos;t know if CVE-2007-1004 has been fixed, that&apos;s unclear.

The most severe vulns belong to NSS, SVG processing in FF2.0, and potential memory corruption in javascript.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-02-24 00:22:58 0000</bug_when>
            <thetext>www-client/mozillafirefox[-bin]-{1.5.0.10,2.0.0.2} in the tree.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-24 08:57:01 0000</bug_when>
            <thetext>Thanks Raul.

Hi, arches, please could you test and mark stable if appropriate :

www-client/mozilla-firefox-1.5.0.10 for all arches except Alpha;
www-client/mozilla-firefox-2.0.0.2 for all arches except Mips;

www-client/mozilla-firefox-bin-1.5.0.10 for amd64 and x86
www-client/mozilla-firefox-bin-2.0.0.2 for amd64 and x86

thanks</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-02-24 11:12:07 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-02-24 11:19:41 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>angelos@gentoo.org</who>
            <bug_when>2007-02-25 17:08:12 0000</bug_when>
            <thetext>tested:
mozilla-firefox-1.5.0.10
mozilla-firefox-2.0.0.2
mozilla-firefox-bin-1.5.0.10
mozilla-firefox-bin-2.0.0.2

everything emerges fine and works

Portage 2.1.2-r9 (default-linux/amd64/2006.1/desktop, gcc-4.1.1, glibc-2.5-r0, 2.6.20-ck1 x86_64)
=================================================================
System uname: 2.6.20-ck1 x86_64 AMD Athlon(tm) 64 X2 Dual Core Processor 4600+
Gentoo Base System release 1.12.9
Timestamp of tree: Sun, 25 Feb 2007 12:50:01 +0000
ccache version 2.4 [enabled]
dev-java/java-config: 1.3.7, 2.0.31
dev-lang/python:     2.4.3-r4
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     2.4-r6
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.61
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.14
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.17-r1
ACCEPT_KEYWORDS=&quot;amd64&quot;
AUTOCLEAN=&quot;yes&quot;
CBUILD=&quot;x86_64-pc-linux-gnu&quot;
CFLAGS=&quot;-march=k8 -O2 -pipe -msse3&quot;
CHOST=&quot;x86_64-pc-linux-gnu&quot;
CONFIG_PROTECT=&quot;/etc /usr/share/X11/xkb&quot;
CONFIG_PROTECT_MASK=&quot;/etc/env.d /etc/env.d/java/ /etc/gconf /etc/java-config/vms/ /etc/revdep-rebuild /etc/terminfo&quot;
CXXFLAGS=&quot;-march=k8 -O2 -pipe -msse3&quot;
DISTDIR=&quot;/usr/portage/distfiles&quot;
FEATURES=&quot;autoconfig builysyspkg ccache distlocks metadata-transfer parallel-fetch sandbox sfperms strict&quot;
GENTOO_MIRRORS=&quot;ftp://linux.rz.ruhr-uni-bochum.de/gentoo-mirror/ ftp://ftp.uni-erlangen.de/pub/mirrors/gentoo ftp://ftp.join.uni-muenster.de/pub/linux/distributions/gentoo ftp://ftp.wh2.tu-dresden.de/pub/mirrors/gentoo ftp://ftp.join.uni-muenster.de/pub/linux/distributions/gentoo ftp://ftp-stud.fht-esslingen.de/pub/Mirrors/gentoo/ ftp://ftp.gentoo.mesh-solutions.com/gentoo/ ftp://pandemonium.tiscali.de/pub/gentoo/ &quot;
LANG=&quot;en_US.ISO-8859-15&quot;
LC_ALL=&quot;en_US.ISO-8859-15&quot;
MAKEOPTS=&quot;-j3&quot;
PKGDIR=&quot;/usr/portage/packages&quot;
PORTAGE_RSYNC_EXTRA_OPTS=&quot;--exclude-from=/etc/portage/rsync_excludes&quot;
PORTAGE_RSYNC_OPTS=&quot;--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages&quot;
PORTAGE_TMPDIR=&quot;/var/tmp&quot;
PORTDIR=&quot;/usr/portage&quot;
PORTDIR_OVERLAY=&quot;/usr/local/portage/overlay&quot;
SYNC=&quot;rsync://rsync.europe.gentoo.org/gentoo-portage&quot;
USE=&quot;X a52 aac acpi alsa amd64 audiofile berkdb bitmap-fonts branding bzip2 cairo cdinstall cdr cli cracklib crypt cups dbus divx dri dvd dvdr dvdread eds emboss encode fam ffmpeg firefox fortran gdbm gif gpm gstreamer gtk gtk2 hal iconv imagemagick ipod jpeg ldap libg++ lirc logrotate mad midi mikmod mp3 mpeg ncurses nls nptl nptlonly offensive ogg opengl pam pcre php png ppds pppd quicktime readline reflection rtc sdl session socks5 spl ssl svg symlink tcpd tiff truetype truetype-fonts type1-fonts unicode v4l v4l2 vim-with-x vorbis wmp xinerama xorg xv xvid zlib&quot; ALSA_CARDS=&quot;emu10k1&quot; ALSA_PCM_PLUGINS=&quot;adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mulaw multi null plug rate route share shm softvol&quot; ELIBC=&quot;glibc&quot; INPUT_DEVICES=&quot;evdev keyboard&quot; KERNEL=&quot;linux&quot; LCD_DEVICES=&quot;bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text&quot; LIRC_DEVICES=&quot;inputlirc&quot; USERLAND=&quot;GNU&quot; VIDEO_CARDS=&quot;fglrx radeon&quot;
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LDFLAGS, LINGUAS</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-02-26 15:37:43 0000</bug_when>
            <thetext>(In reply to comment #5)
&gt; www-client/mozilla-firefox-1.5.0.10 for all arches except Alpha;
&gt; www-client/mozilla-firefox-2.0.0.2 for all arches except Mips;

Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2007-02-27 02:32:22 0000</bug_when>
            <thetext>Stable on SPARC</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2007-02-27 12:45:20 0000</bug_when>
            <thetext>amd64 stable, thanks Christoph</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2007-02-27 12:46:28 0000</bug_when>
            <thetext>Hum, still have to do seamonkey{,-bin} on amd64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-27 13:45:02 0000</bug_when>
            <thetext>update of the vulnerability list:

http://www.mozilla.org/security/announce/2007/mfsa2007-08.html
CVE-2007-1092 affects FF and SM.
(memory corruption)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-27 13:48:37 0000</bug_when>
            <thetext>(In reply to comment #12)
&gt; Hum, still have to do seamonkey{,-bin} on amd64.
&gt; 

Well i don&apos;t know if samonkey-1.1  is affected or not. It&apos;s rather old (&gt;1 month ago) but it is not referenced in the MFSA.

CVE entries are still closed, only FF is released, we have no news for seamonkey-1.0.8 and TB-1.5.0.10 and 2.0.0.2, ... but some other distributions have issued updates for seamonkey and thunderbird, i don&apos;t know how!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>neeo@xl.wp.pl</who>
            <bug_when>2007-02-28 12:47:09 0000</bug_when>
            <thetext>SeaMonkey 1.0.8 and 1.1.1 have been released... (http://www.mozilla.org/projects/seamonkey/releases/)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-02-28 19:45:35 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-28 20:26:01 0000</bug_when>
            <thetext>Hi again arches, 

seamonkey[-bin] has just been put into portage.

-1.0.8 and -1.1.1 fix all the known vulnerabilities.

Please could you test and mark stable if appropriate:

seamonkey-1.1.1 in preference (1.0.8 otherwise)
seamonkey-bin-1.1.1 (there is no 1.0.8 in the tree) for AMD64+X86


and we&apos;re still waiting for alpha on mozilla-firefox, but don&apos;t worry since the GLSA is not ready yet :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-02-28 21:16:50 0000</bug_when>
            <thetext>seamonkey[-bin] x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>angelos@gentoo.org</who>
            <bug_when>2007-02-28 21:22:17 0000</bug_when>
            <thetext>seamonkey{,-bin} emerge and work fine on amd64

Portage 2.1.2-r9 (default-linux/amd64/2006.1/desktop, gcc-4.1.1, glibc-2.5-r0, 2.6.20-ck1 x86_64)
=================================================================
System uname: 2.6.20-ck1 x86_64 AMD Athlon(tm) 64 X2 Dual Core Processor 4600+
Gentoo Base System release 1.12.9
Timestamp of tree: Wed, 28 Feb 2007 20:20:01 +0000
ccache version 2.4 [enabled]
dev-java/java-config: 1.3.7, 2.0.31
dev-lang/python:     2.4.3-r4
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     2.4-r6
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.61
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.14
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.17-r1
ACCEPT_KEYWORDS=&quot;amd64&quot;
AUTOCLEAN=&quot;yes&quot;
CBUILD=&quot;x86_64-pc-linux-gnu&quot;
CFLAGS=&quot;-march=k8 -O2 -pipe -msse3&quot;
CHOST=&quot;x86_64-pc-linux-gnu&quot;
CONFIG_PROTECT=&quot;/etc /usr/share/X11/xkb&quot;
CONFIG_PROTECT_MASK=&quot;/etc/env.d /etc/env.d/java/ /etc/gconf /etc/java-config/vms/ /etc/revdep-rebuild /etc/terminfo&quot;
CXXFLAGS=&quot;-march=k8 -O2 -pipe -msse3&quot;
DISTDIR=&quot;/usr/portage/distfiles&quot;
FEATURES=&quot;autoconfig buildsyspkg ccache collision-protect distlocks metadata-transfer multilib-strict parallel-fetch sandbox sfperms strict test&quot;
GENTOO_MIRRORS=&quot;ftp://linux.rz.ruhr-uni-bochum.de/gentoo-mirror/ ftp://ftp.uni-erlangen.de/pub/mirrors/gentoo ftp://ftp.join.uni-muenster.de/pub/linux/distributions/gentoo ftp://ftp.wh2.tu-dresden.de/pub/mirrors/gentoo ftp://ftp.join.uni-muenster.de/pub/linux/distributions/gentoo ftp://ftp-stud.fht-esslingen.de/pub/Mirrors/gentoo/ ftp://ftp.gentoo.mesh-solutions.com/gentoo/ ftp://pandemonium.tiscali.de/pub/gentoo/ &quot;
LANG=&quot;en_US.ISO-8859-15&quot;
LC_ALL=&quot;en_US.ISO-8859-15&quot;
MAKEOPTS=&quot;-j3&quot;
PKGDIR=&quot;/usr/portage/packages&quot;
PORTAGE_RSYNC_EXTRA_OPTS=&quot;--exclude-from=/etc/portage/rsync_excludes&quot;
PORTAGE_RSYNC_OPTS=&quot;--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages&quot;
PORTAGE_TMPDIR=&quot;/var/tmp&quot;
PORTDIR=&quot;/usr/portage&quot;
PORTDIR_OVERLAY=&quot;/usr/local/portage/overlay&quot;
SYNC=&quot;rsync://rsync.europe.gentoo.org/gentoo-portage&quot;
USE=&quot;X a52 aac acpi alsa amd64 audiofile berkdb bitmap-fonts branding bzip2 cairo cdinstall cdr cli cracklib crypt cups dbus divx dri dvd dvdr dvdread eds emboss encode fam ffmpeg firefox fortran gdbm gif gpm gstreamer gtk gtk2 hal iconv imagemagick ipod jpeg ldap libg++ lirc logrotate mad midi mikmod mp3 mpeg ncurses nls nptl nptlonly offensive ogg opengl pam pcre php png ppds pppd quicktime readline reflection rtc sdl session socks5 spl ssl svg symlink tcpd test tiff truetype truetype-fonts type1-fonts unicode v4l v4l2 vim-with-x vorbis wmp xinerama xorg xv xvid zlib&quot; ALSA_CARDS=&quot;emu10k1&quot; ALSA_PCM_PLUGINS=&quot;adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mulaw multi null plug rate route share shm softvol&quot; ELIBC=&quot;glibc&quot; INPUT_DEVICES=&quot;evdev keyboard&quot; KERNEL=&quot;linux&quot; LCD_DEVICES=&quot;bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text&quot; LIRC_DEVICES=&quot;inputlirc&quot; USERLAND=&quot;GNU&quot; VIDEO_CARDS=&quot;fglrx radeon&quot;
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LDFLAGS, LINGUAS</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>yoswink@gentoo.org</who>
            <bug_when>2007-02-28 23:13:35 0000</bug_when>
            <thetext>mozilla-firefox-2.0.0.2 is stable on alpha.

Working on seamonkey now.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>neeo@xl.wp.pl</who>
            <bug_when>2007-03-01 10:11:40 0000</bug_when>
            <thetext>could you please bump Enigmail as well? &quot;11/01/2007 Enigmail v0.94.2 has been released. A crash bug that could affect security has been fixed.&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2007-03-01 12:46:43 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-03-01 15:25:41 0000</bug_when>
            <thetext>(In reply to comment #21)
&gt; could you please bump Enigmail as well? &quot;11/01/2007 Enigmail v0.94.2 has been
&gt; released. A crash bug that could affect security has been fixed.&quot;
&gt; 

Already bumped 2 weeks ago, see bug 166932. (and it is not the right place)

Since it&apos;s a client-side DoS, without any further information, we won&apos;t handle it as a security issue. Feel free to reopen bug 166932 if you can bring clue of code injection or so.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>neeo@xl.wp.pl</who>
            <bug_when>2007-03-01 22:38:19 0000</bug_when>
            <thetext>well, i see enigmail 0.94.2 is in portage, but SeaMonkey&apos;s 1.1.1 ebuild still uses 0.94.1 (with USE=&quot;crypt&quot;).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-03-02 04:50:24 0000</bug_when>
            <thetext>Stable for HPPA:
   =www-client/mozilla-firefox-1.5.0.10
   =www-client/mozilla-firefox-2.0.0.2
   =www-client/seamonkey-1.1.1 (killerfox)

Anything else?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-03-02 22:33:02 0000</bug_when>
            <thetext>Readding amd64, sparc and x86, as ebuild is ready and Falco busy torturing new recruits.

mozilla-thunderbird[-bin]-15.0.10 needs to go stable, too.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-03-02 22:40:09 0000</bug_when>
            <thetext>x86 stable!

See you when nss is released...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-03-03 12:43:31 0000</bug_when>
            <thetext>seamonkey also ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-03-03 15:59:23 0000</bug_when>
            <thetext>(In reply to comment #26)
&gt; Readding amd64, sparc and x86, as ebuild is ready and Falco busy torturing new
&gt; recruits.
&gt; 
&gt; mozilla-thunderbird[-bin]-15.0.10 needs to go stable, too.
&gt; 

amd64 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>yoswink@gentoo.org</who>
            <bug_when>2007-03-03 18:47:43 0000</bug_when>
            <thetext>seamonkey-1.1.1 stable on alpha. 

working on thunderbird</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-03-04 00:30:58 0000</bug_when>
            <thetext>Firefox -&gt; GLSA 200703-04</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-03-04 01:26:51 0000</bug_when>
            <thetext>Wake me up for NSS.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>yoswink@gentoo.org</who>
            <bug_when>2007-03-05 21:00:22 0000</bug_when>
            <thetext>thunderbird stable on alpha.

See you in the next round.

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-03-06 13:55:14 0000</bug_when>
            <thetext>thunderbird sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-03-07 21:37:52 0000</bug_when>
            <thetext>Hello again arches.

Please stabilize =dev-libs/nss-3.11.5. Please note that YOU NEED to stabilize =dev-libs/nspr-4.6.5-r1 first -&gt; bug 169751

And this will be the last one :)

Thanks!

x86 stable
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-03-08 08:14:23 0000</bug_when>
            <thetext>ppc64 stable (nss-3.11.5)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-03-08 14:07:47 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-03-08 17:38:14 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>beandog@gentoo.org</who>
            <bug_when>2007-03-08 22:16:12 0000</bug_when>
            <thetext>(In reply to comment #35)
&gt; Hello again arches.
&gt; 
&gt; Please stabilize =dev-libs/nss-3.11.5. Please note that YOU NEED to stabilize
&gt; =dev-libs/nspr-4.6.5-r1 first -&gt; bug 169751
&gt; 
&gt; And this will be the last one :)
&gt; 
&gt; Thanks!

amd64 stable

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>neeo@xl.wp.pl</who>
            <bug_when>2007-03-08 22:48:26 0000</bug_when>
            <thetext>&quot;06/03/2007 Important Security fix for Enigmail. A security bug detected by Core Security Technologies has been fixed in Enigmail v0.94.3.&quot;
Maybe now it&apos;s time to update SeaMonkey&apos;s ebuild, and bump EMVER to &quot;0.94.3&quot;?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-03-09 02:28:15 0000</bug_when>
            <thetext>=dev-libs/nss-3.11.5 stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-03-09 11:52:35 0000</bug_when>
            <thetext>(In reply to comment #40)
&gt; &quot;06/03/2007 Important Security fix for Enigmail. A security bug detected by
&gt; Core Security Technologies has been fixed in Enigmail v0.94.3.&quot;
&gt; Maybe now it&apos;s time to update SeaMonkey&apos;s ebuild, and bump EMVER to &quot;0.94.3&quot;?
Our security team is working on that. 

And SeaMonkey will not get other version of Enigmail unless Enigmail standalone have the same keywords as SeaMonkey.

Anyway, this bug is not related to that security issue.

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-03-10 16:37:42 0000</bug_when>
            <thetext>SeaMonkey -&gt; GLSA 200703-08, thanks everybody</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2007-03-11 01:01:00 0000</bug_when>
            <thetext>Alpha + IA64 all done.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-03-13 23:18:15 0000</bug_when>
            <thetext>CCing back Alpha for stabilizing NSS-3.11.5, thanks.

Seamonkey and NSS GLSA in the draft pool.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-03-14 11:43:31 0000</bug_when>
            <thetext>(In reply to comment #45)
&gt; CCing back Alpha for stabilizing NSS-3.11.5, thanks.
&gt; 
&gt; Seamonkey and NSS GLSA in the draft pool.
&gt; 

Alpha and IA64 were stable, but i put it back to ~arch by mistake. Fixed now :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-03-18 22:03:25 0000</bug_when>
            <thetext>thunderbird -&gt; GLSA 200701-18</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-03-21 18:46:04 0000</bug_when>
            <thetext>ppc, you need to stabilize mozilla-thunderbird-1.5.0.10.

Thanks.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-03-23 16:15:17 0000</bug_when>
            <thetext>(In reply to comment #48)
&gt; ppc, you need to stabilize mozilla-thunderbird-1.5.0.10.
&gt; 
&gt; Thanks.
&gt; 

ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-25 07:50:54 0000</bug_when>
            <thetext>GLSA 200703-22</thetext>
          </long_desc>
      
    </bug>

</bugzilla>