http://www.mozilla.org/security/announce/2007/mfsa2007-17.html http://www.mozilla.org/security/announce/2007/mfsa2007-16.html http://www.mozilla.org/security/announce/2007/mfsa2007-15.html http://www.mozilla.org/security/announce/2007/mfsa2007-14.html http://www.mozilla.org/security/announce/2007/mfsa2007-13.html http://www.mozilla.org/security/announce/2007/mfsa2007-12.html Are fixed in: www-client/mozilla-firefox[-bin]-[1.5.0.12,2.0.0.4] www-client/seamonkey[-bin]-[1.0.9,1.1.2] mail-client/mozilla-thunderbird-[bin]-[1.5.0.12,2.0.0.4]
*** Bug 175021 has been marked as a duplicate of this bug. ***
xulrunner is affected too and is fixed in 1.8.1.4
*** Bug 180406 has been marked as a duplicate of this bug. ***
www-client/mozilla-firefox[-bin]-2.0.0.4 www-client/seamonkey[-bin]-1.1.2 mail-client/mozilla-thunderbird-[bin]-1.5.0.12 Are in the tree. firefox-1.5.0.12 is discontinued, so it's not going to be in the tree. I didn't put seamonkey-1.0.9 either, i'd prefer to use 1.1.2 thunderbird-2.0.0.4 is not yet released. xulrunner will have to wait as we can work out the patches.
Created attachment 120833 [details] xulrunner-1.8.1.4-patches-0.1.tar.bz2 reference xulrunner-1.8.1.4 patchset: svn stat D 065_firefox-libgtkmozembeded.patch - applied upstream M 125_gnome_helpers_with_params.patch - some parts redone D 070_dont_use_bashism.patch - applied upstream D 009_firefox-1.5-no-textrels.patch - applied upstream M 161_javaxpcom.patch - one of the patches was included upstream A 620_python_extension_rpath.patch added for bug #180309 125_gnome_helpers_with_params.patch is the most critical as the logic upstream was changed in one of the patched files - I backed parts of the patch as the new logic was more or less equal to the one in the previous patch Hope this could help
xulrunner-1.8.1.4 on cvs, thanks as always Gergan :)
Hi arches, please could you test and mark stable the following ebuilds, due to security upgrades for the Mozilla products. All ebuilds are not in the tree yet, i'll CC you again when they are. Thanks in advance. alpha amd64 arm hppa ia64 mips ppc ppc64 sparc x86: mozilla-firefox-2.0.0.4 amd64 x86 mozilla-firefox-bin-2.0.0.4 alpha amd64 arm hppa ia64 ppc ppc64 x86: www-client/seamonkey-1.1.2 amd64 x86 www-client/seamonkey-bin-1.1.2 alpha amd64 ia64 mips ppc sparc x86: mail-client/mozilla-thunderbird-1.5.0.12 amd64 x86: mail-client/mozilla-thunderbird-bin-1.5.0.12 amd64 ia64 ppc sparc x86: net-libs/xulrunner-1.8.1.4
aaah i hate that interface and its middle-air collisions (hi arches, please see previous comment)
amd64 done
alpha/ia64/x86 stable
stable on ppc.
ppc64 stable
sparc done.
Despite the issues of bug #180870, all can be built against by working GUIs so stable all around for HPPA for: www-client/mozilla-firefox-2.0.0.4 www-client/seamonkey-1.1.2 net-libs/xulrunner-1.8.1.4
thanks arches
Moz team, i don't see mozilla-thunderbird[-bin]-2.0.0.4 in the tree. The latest stable version on most arches in still vulnerable (2.0.0.0). Please could you do your magic, thanks. Furthermore, do you have a reason we can add in our GLSA for the stopped support of mozilla-firefox-1.5.*? thanks
(In reply to comment #17) > Moz team, i don't see mozilla-thunderbird[-bin]-2.0.0.4 in the tree. The latest > stable version on most arches in still vulnerable (2.0.0.0). Please could you > do your magic, thanks. > > Furthermore, do you have a reason we can add in our GLSA for the stopped > support of mozilla-firefox-1.5.*? thanks > mozilla-thunderbird-2.0.0.4 is not out yet. Probably it will be released during this week. mozilla-firefox-1.5.* is unsupported both upstream and both Gentoo, since 2.0 have been working fine on all arches since October 2006 and it has been already stable on those arches.
ppc you need to do xulrunner
(In reply to comment #19) > ppc you need to do xulrunner > once again: ppc stable
(In reply to comment #18) > mozilla-thunderbird-2.0.0.4 is not out yet. Probably it will be released during > this week. it's out
=mail-client/mozilla-thunderbird[-bin]-2.0.0.4 in the tree
Hi again arches, please could you test and mark mozilla-thunderbird[-bin]-2.0.0.4 stable, thanks
ppc stable
sparc stable.
ready for glsa
GLSA 200706-06, thanks everybody!