First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 63996
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Carsten Lohrke <carlo@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 63996 depends on: Show dependency tree
Bug 63996 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-09-14 07:18 0000
http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3

------- Comment #1 From Thierry Carrez (RETIRED) 2004-09-14 07:31:36 0000 -------
Mozilla team, please provide new ebuilds for :

net-www/mozilla
net-www/mozilla-bin
net-www/mozilla-firefox
net-www/mozilla-firefox-bin
mail-client/mozilla-thunderbird
mail-client/mozilla-thunderbird-bin

Gnome team, please check the following ebuilds to see if bumps are needed to make them use the latest Gecko :

net-www/epiphany
net-www/galeon

------- Comment #2 From foser (RETIRED) 2004-09-14 07:39:32 0000 -------
CC hanno for galeon

------- Comment #3 From Lars Wendler (Polynomial-C) 2004-09-15 01:12:11 0000 -------
*** Bug 64095 has been marked as a duplicate of this bug. ***

------- Comment #4 From Jason Short 2004-09-15 11:25:53 0000 -------
ebumped -bin ebuilds, they Just Work(tm)

source ebuilds for firefox and thunderbird require rearrangement of the SRC_URI, someone at mozilla can't decide to call it "source-${PV}" or "${PV}-source"

additionally, firefox and thunderbird compiles die unless configured with --enable-single-profile, which effectively clobbers the ability to run concurrent sessions from different profiles.

have not yet had the occasion to test moz 1.7.3 build for the same problem

------- Comment #5 From Aron Griffis (RETIRED) 2004-09-15 13:39:01 0000 -------
In portage now, marked ~arch:

net-www/mozilla-1.7.3
net-www/mozilla-bin-1.7.3
net-www/mozilla-firefox-1.0_pre
net-www/mozilla-firefox-bin-1.0_pre
mail-client/mozilla-thunderbird-0.8
mail-client/mozilla-thunderbird-bin-0.8

------- Comment #6 From Thierry Carrez (RETIRED) 2004-09-15 14:06:46 0000 -------
Arches, please mark stable :

x86,amd64 : mozilla-1.7.3 mozilla-firefox-1.0_pre mozilla-firefox-bin-1.0_pre mozilla-thunderbird
ppc : mozilla-1.7.3 mozilla-firefox-1.0_pre
sparc,alpha,ia64 : mozilla-1.7.3 mozilla-firefox-1.0_pre mozilla-thunderbird

------- Comment #7 From Olivier Crete 2004-09-15 15:31:43 0000 -------
mozilla-bin and mozilla-firefox-bin are there for x86.. (for ppl who want a
quick fix)

------- Comment #8 From Jochen Maes (RETIRED) 2004-09-16 04:57:06 0000 -------
stable on ppc

------- Comment #9 From Tobias Sager 2004-09-16 06:13:32 0000 -------
Also see bug 63850.

------- Comment #10 From Gustavo Zacarias (RETIRED) 2004-09-16 06:56:27 0000 -------
mozilla-1.7.3 sparc stable.
FYI, epiphany-1.2.7-r1 and galeon-1.3.17 work just fine in upgrade and rebuild scenarios.
Also repoman complains about file.size on:
(27K) net-www/mozilla/files/gtk2mozilla_head_patch2
(35K) net-www/mozilla/files/mozilla-1.4-amd64.patch
(25K) net-www/mozilla/files/mozilla-1.7-amd64.patch

------- Comment #11 From foser (RETIRED) 2004-09-16 07:52:22 0000 -------
added epiphany-1.2.9-r1 to ~arch with patch to build to & dep on 1.7.3 

------- Comment #12 From Thierry Carrez (RETIRED) 2004-09-16 08:20:24 0000 -------
Updating call for arches to test and mark stable with epiphany. Still needed :

x86 :
net-www/mozilla-1.7.3
net-www/mozilla-firefox-1.0_pre
net-www/epiphany-1.2.9-r1

amd64 :
net-www/mozilla-1.7.3
net-www/mozilla-firefox-1.0_pre
net-www/mozilla-firefox-bin-1.0_pre
net-www/epiphany-1.2.9-r1

ppc :
net-www/epiphany-1.2.9-r1

sparc :
net-www/mozilla-firefox-1.0_pre
net-www/epiphany-1.2.9-r1

alpha, ia64 :
net-www/mozilla-1.7.3
net-www/mozilla-firefox-1.0_pre
net-www/epiphany-1.2.9-r1

There will be a galeon update to test in the near future.

------- Comment #13 From Gustavo Zacarias (RETIRED) 2004-09-16 08:27:19 0000 -------
mozilla-firefox-1.0_pre sparc stable.
we're looking into some issues with mozilla-thunderbird-0.8 which was keyworded as stable when bumped. more on this later.

------- Comment #14 From Lars Wendler (Polynomial-C) 2004-09-16 08:32:10 0000 -------
Hi,

tested mozilla-1.7.3 for three days now on two x86 machines. Not one songle crash of mozilla compiled with these useflags: +crypt -debug -gnome +gtk2 +java -ldap -mozcalendar -mozdevelop +moznocompose +moznoirc +moznomail -moznoxft -mozsvg -mozxmlterm +ssl -xinerama +xprint

Poly

------- Comment #15 From Travis Tilley (RETIRED) 2004-09-16 12:44:53 0000 -------
those amd64 patches can be removed if the 1.6 and early 1.7 ebuilds are removed
(which they should be)

------- Comment #16 From Gustavo Zacarias (RETIRED) 2004-09-16 12:59:24 0000 -------
epiphany-1.2.9-r1 sparc stable.

------- Comment #17 From Jochen Maes (RETIRED) 2004-09-17 01:35:41 0000 -------
epiphany stable on ppc

------- Comment #18 From Hanno Boeck 2004-09-17 05:28:57 0000 -------
galeon-1.3.17 doesn't need to be rebuild with 1.7.3 and builds fine against it,
so imho no need to change anything here.
I'll make it dep on >=mozilla-1.7.3 as soon as all archs marked 1.7.3 stable.

------- Comment #19 From Thierry Carrez (RETIRED) 2004-09-17 14:07:54 0000 -------
sparc, ppc: thanks :)

Hanno : does it mean you don't need to update galeon to be protected, you just need to update the other packages ? If you need to rebuild galeon to take advantage of the fix, we'll need a revbump to force the upgrade, if not, we're set.

Stable still needed on :

x86 :
net-www/mozilla-1.7.3
net-www/mozilla-firefox-1.0_pre
net-www/epiphany-1.2.9-r1

amd64 :
net-www/epiphany-1.2.9-r1

alpha, ia64 :
net-www/mozilla-1.7.3
net-www/mozilla-firefox-1.0_pre
net-www/epiphany-1.2.9-r1

------- Comment #20 From Olivier Crete 2004-09-17 14:17:47 0000 -------
firefox is there for x86.. testing mozilla now..

------- Comment #21 From Olivier Crete 2004-09-17 21:00:22 0000 -------
mozilla 1.7.3 is there for x86.. but epiphany doesnt work with the realplayer8
plug-in.. is that normal ?
I get
LoadPlugin: failed to initialize shared library /opt/RealPlayer8/rpnp.so
[/opt/RealPlayer8/rpnp.so: undefined symbol: __pure_virtual]

(I actually get the same error with firefox-bin...)

------- Comment #22 From Karol Wojtaszek (RETIRED) 2004-09-18 04:04:18 0000 -------
I think you shouldn't stabilize firefox-1.0pr, because it still contains many
bugs in UI. You should add 0.9.3-r1 with patches that they'll fix
vulnerabilities.

------- Comment #23 From Bryan Østergaard (RETIRED) 2004-09-19 05:42:33 0000 -------
Alpha done.

------- Comment #24 From foser (RETIRED) 2004-09-19 05:55:36 0000 -------
epiphany-1.2.9-r1 x86 done

------- Comment #25 From Olivier Crete 2004-09-19 15:00:59 0000 -------
all done on x86

------- Comment #26 From Luke Macken (RETIRED) 2004-09-19 22:59:46 0000 -------
*** Bug 64182 has been marked as a duplicate of this bug. ***

------- Comment #27 From Thierry Carrez (RETIRED) 2004-09-20 00:34:27 0000 -------
GLSA ready, blocked by amd64 needing to mark epiphany-1.2.9-r1 stable.

------- Comment #28 From Malcolm Lashley (RETIRED) 2004-09-20 08:49:15 0000 -------
stable on amd64

------- Comment #29 From Thierry Carrez (RETIRED) 2004-09-20 09:00:25 0000 -------
GLSA drafted, security, please review

------- Comment #30 From Thierry Carrez (RETIRED) 2004-09-20 13:57:23 0000 -------
Thx everyone
GLSA 200409-26 is out

First Last Prev Next    No search results available      Search page      Enter new bug