Subject: pkg/26594: update mozilla and mozilla-gtk2 to 1.7.2
To: None <gnats-bugs@gnats.NetBSD.org>
From: None <hira@po6.nsk.ne.jp>
List: pkgsrc-bugs
Date: 08/08/2004 22:55:17
>Number: 26594
>Category: pkg
>Synopsis: update mozilla and mozilla-gtk2 to 1.7.2
>Confidential: no
>Severity: serious
>Priority: medium
>Responsible: pkg-manager
>State: open
>Class: change-request
>Submitter-Id: net
>Arrival-Date: Sun Aug 08 14:07:00 UTC 2004
>Closed-Date:
>Last-Modified:
>Originator: Kouichirou Hiratsuka
>Release: NetBSD 2.0G
>Organization:
>Environment:
System: NetBSD firefly.localdomain 2.0G NetBSD 2.0G (FIREFLY.MP) #51: Sun Aug 8 18:03:10 JST 2004 root@firefly.localdomain:/usr/src/sys/arch/i386/compile/FIREFLY.MP i386
Architecture: i386
Machine: i386
>Description:
Mozilla 1.7.2 was released on Aug. 4. Three security vulnerabilities
have been fixed.
- Importing false CA certificate leading to error -8182 (perm DoS),
especially exploitable by email (#249004)
- lock icon and certificates spoofable with onunload document.write
(#253121)
- new libpng buffer overflow vulnerabilities (#251381)
>How-To-Repeat:
>Fix:
Index: mozilla/Makefile
===================================================================
RCS file: /cvs/cvsroot/pkgsrc/www/mozilla/Makefile,v
retrieving revision 1.135
diff -u -r1.135 Makefile
--- mozilla/Makefile 5 Jul 2004 14:22:42 -0000 1.135
+++ mozilla/Makefile 7 Aug 2004 21:41:54 -0000
@@ -2,8 +2,7 @@
MOZILLA= mozilla
MOZILLA_BIN= mozilla-bin
-MOZ_VER= 1.7
-PKGREVISION= 1
+MOZ_VER= 1.7.2
EXTRACT_SUFX= .tar.bz2
DISTFILES= ${DISTNAME}${EXTRACT_SUFX}
Index: mozilla/distinfo
===================================================================
RCS file: /cvs/cvsroot/pkgsrc/www/mozilla/distinfo,v
retrieving revision 1.61
diff -u -r1.61 distinfo
--- mozilla/distinfo 26 Jul 2004 23:36:01 -0000 1.61
+++ mozilla/distinfo 8 Aug 2004 11:03:44 -0000
@@ -1,7 +1,7 @@
$NetBSD: distinfo,v 1.61 2004/07/26 23:36:01 taya Exp $
-SHA1 (mozilla-source-1.7.tar.bz2) = 52b8ab9248a8f4ed5763d7715f4fa18bda8123cf
-Size (mozilla-source-1.7.tar.bz2) = 35174502 bytes
+SHA1 (mozilla-source-1.7.2.tar.bz2) = 75c6f68d198e2fe0b7be525af6d458cc07c7d48d
+Size (mozilla-source-1.7.2.tar.bz2) = 34438800 bytes
SHA1 (patch-aa) = be62070f062e8ae13f06bd7b3f4f0d4a9ee67bef
SHA1 (patch-ab) = 334a1e79d63d045dafb50b82ea192b311b55e7d5
SHA1 (patch-ac) = 32aa4b92eea19aca07077a292cb759d074026642
Index: mozilla-gtk2/Makefile
===================================================================
RCS file: /cvs/cvsroot/pkgsrc/www/mozilla-gtk2/Makefile,v
retrieving revision 1.10
diff -u -r1.10 Makefile
--- mozilla-gtk2/Makefile 5 Jul 2004 14:23:53 -0000 1.10
+++ mozilla-gtk2/Makefile 7 Aug 2004 20:30:57 -0000
@@ -2,8 +2,7 @@
MOZILLA= mozilla-gtk2
MOZILLA_BIN= mozilla-bin
-MOZ_VER= 1.7
-PKGREVISION= 1
+MOZ_VER= 1.7.2
EXTRACT_SUFX= .tar.bz2
DISTFILES= ${DISTNAME}${EXTRACT_SUFX}
>Release-Note:
>Audit-Trail:
>Unformatted: