pkgsrc-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

pkg/38610: Security update for thunderbird



>Number:         38610
>Category:       pkg
>Synopsis:       Security update for thunderbird
>Confidential:   no
>Severity:       critical
>Priority:       high
>Responsible:    pkg-manager
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Thu May 08 12:00:00 +0000 2008
>Originator:     César Catrián Carreño
>Release:        NetBSD 4.99.44 i386
>Organization:
>Environment:


System: NetBSD 4.99.44 (Basado en GENERIC: 1.781) #0: Sat Mar 22 18:07:59 CLT 
2008
        
cetrox%core.cjc.cl@localhost:/home/cetrox/src/netbsd-current/src/sys/arch/i386/compile/SAT



>Description:


This update fixes an arbitrary-code-execution vulnerability ( 
http://www.mozilla.org/security/announce/2008/mfsa2008-14.html ), and a 
remote-system-access vulnerability ( 
http://www.mozilla.org/security/announce/2008/mfsa2008-20.html ).


>How-To-Repeat:





>Fix:


--- mail/thunderbird/Makefile-thunderbird.common.orig   2008-05-07 
21:42:08.000000000 -0400
+++ mail/thunderbird/Makefile-thunderbird.common        2008-05-07 
21:42:16.000000000 -0400
@@ -1,7 +1,7 @@
 # $NetBSD: Makefile-thunderbird.common,v 1.33 2008/02/27 10:00:47 ghen Exp $
 
 MOZILLA_BIN=           thunderbird-bin
-MOZ_VER=               2.0.0.12
+MOZ_VER=               2.0.0.14
 EXTRACT_SUFX=          .tar.bz2
 DISTNAME=              thunderbird-${MOZ_VER}-source
 CATEGORIES=            mail


--- mail/thunderbird/distinfo.orig      2008-05-07 21:55:27.000000000 -0400
+++ mail/thunderbird/distinfo   2008-05-07 21:55:58.000000000 -0400
@@ -1,8 +1,8 @@
 $NetBSD: distinfo,v 1.43 2008/02/27 10:00:47 ghen Exp $
 
-SHA1 (thunderbird-2.0.0.12-source.tar.bz2) = 
36ea64353d32a9f138ef658250cfdcf8f9e862f2
-RMD160 (thunderbird-2.0.0.12-source.tar.bz2) = 
80d6fdb4b8e085a82234825cfbfc6cd05d015f6f
-Size (thunderbird-2.0.0.12-source.tar.bz2) = 37485204 bytes
+SHA1 (thunderbird-2.0.0.14-source.tar.bz2) = 
5f30f6e54895e67d96304cdbce15e69aee4d3230
+RMD160 (thunderbird-2.0.0.14-source.tar.bz2) = 
b7a61bfe9b3b06fc26051e97e7ca4da0b7ab64a4
+Size (thunderbird-2.0.0.14-source.tar.bz2) = 37473129 bytes
 SHA1 (patch-aa) = ff3586c00ff8d3fa6a1bda639116778169ad4466
 SHA1 (patch-ab) = 1dda9cc5822761da53133e987e30c133894baad7
 SHA1 (patch-ac) = 24da4ecce48d22a3752276cae132845b4b474c2a





Home | Main Index | Thread Index | Old Index