Summary: | www-client/(mozilla-firefox|seamonkey)(-bin),mail-client/thunderbird(-bin),net-libs/xulrunner: Security release (CVE-2007-1362,1558,286[789],287[01]) | ||||||
---|---|---|---|---|---|---|---|
Product: | Gentoo Security | Reporter: | Raúl Porcel (RETIRED) <armin76> | ||||
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> | ||||
Status: | RESOLVED FIXED | ||||||
Severity: | major | CC: | jaervosz, mozilla, sgtphou | ||||
Priority: | High | ||||||
Version: | unspecified | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | A2 [glsa] Falco | ||||||
Package list: | Runtime testing required: | --- | |||||
Attachments: |
|
Description
Raúl Porcel (RETIRED)
![]() *** Bug 175021 has been marked as a duplicate of this bug. *** xulrunner is affected too and is fixed in 1.8.1.4 *** Bug 180406 has been marked as a duplicate of this bug. *** www-client/mozilla-firefox[-bin]-2.0.0.4 www-client/seamonkey[-bin]-1.1.2 mail-client/mozilla-thunderbird-[bin]-1.5.0.12 Are in the tree. firefox-1.5.0.12 is discontinued, so it's not going to be in the tree. I didn't put seamonkey-1.0.9 either, i'd prefer to use 1.1.2 thunderbird-2.0.0.4 is not yet released. xulrunner will have to wait as we can work out the patches. Created attachment 120833 [details] xulrunner-1.8.1.4-patches-0.1.tar.bz2 reference xulrunner-1.8.1.4 patchset: svn stat D 065_firefox-libgtkmozembeded.patch - applied upstream M 125_gnome_helpers_with_params.patch - some parts redone D 070_dont_use_bashism.patch - applied upstream D 009_firefox-1.5-no-textrels.patch - applied upstream M 161_javaxpcom.patch - one of the patches was included upstream A 620_python_extension_rpath.patch added for bug #180309 125_gnome_helpers_with_params.patch is the most critical as the logic upstream was changed in one of the patched files - I backed parts of the patch as the new logic was more or less equal to the one in the previous patch Hope this could help xulrunner-1.8.1.4 on cvs, thanks as always Gergan :) Hi arches, please could you test and mark stable the following ebuilds, due to security upgrades for the Mozilla products. All ebuilds are not in the tree yet, i'll CC you again when they are. Thanks in advance. alpha amd64 arm hppa ia64 mips ppc ppc64 sparc x86: mozilla-firefox-2.0.0.4 amd64 x86 mozilla-firefox-bin-2.0.0.4 alpha amd64 arm hppa ia64 ppc ppc64 x86: www-client/seamonkey-1.1.2 amd64 x86 www-client/seamonkey-bin-1.1.2 alpha amd64 ia64 mips ppc sparc x86: mail-client/mozilla-thunderbird-1.5.0.12 amd64 x86: mail-client/mozilla-thunderbird-bin-1.5.0.12 amd64 ia64 ppc sparc x86: net-libs/xulrunner-1.8.1.4 aaah i hate that interface and its middle-air collisions (hi arches, please see previous comment) aaah i hate that interface and its middle-air collisions (hi arches, please see previous comment) amd64 done alpha/ia64/x86 stable stable on ppc. ppc64 stable sparc done. Despite the issues of bug #180870, all can be built against by working GUIs so stable all around for HPPA for: www-client/mozilla-firefox-2.0.0.4 www-client/seamonkey-1.1.2 net-libs/xulrunner-1.8.1.4 thanks arches Moz team, i don't see mozilla-thunderbird[-bin]-2.0.0.4 in the tree. The latest stable version on most arches in still vulnerable (2.0.0.0). Please could you do your magic, thanks. Furthermore, do you have a reason we can add in our GLSA for the stopped support of mozilla-firefox-1.5.*? thanks (In reply to comment #17) > Moz team, i don't see mozilla-thunderbird[-bin]-2.0.0.4 in the tree. The latest > stable version on most arches in still vulnerable (2.0.0.0). Please could you > do your magic, thanks. > > Furthermore, do you have a reason we can add in our GLSA for the stopped > support of mozilla-firefox-1.5.*? thanks > mozilla-thunderbird-2.0.0.4 is not out yet. Probably it will be released during this week. mozilla-firefox-1.5.* is unsupported both upstream and both Gentoo, since 2.0 have been working fine on all arches since October 2006 and it has been already stable on those arches. ppc you need to do xulrunner (In reply to comment #19) > ppc you need to do xulrunner > once again: ppc stable (In reply to comment #18) > mozilla-thunderbird-2.0.0.4 is not out yet. Probably it will be released during > this week. it's out =mail-client/mozilla-thunderbird[-bin]-2.0.0.4 in the tree Hi again arches, please could you test and mark mozilla-thunderbird[-bin]-2.0.0.4 stable, thanks alpha/ia64/x86 stable amd64 done ppc stable ppc64 stable sparc stable. ready for glsa GLSA 200706-06, thanks everybody! |