pkgsrc-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[pkgsrc/trunk]: pkgsrc/www Update seamonkey, seamonkey-bin and seamonkey-gtk1...



details:   https://anonhg.NetBSD.org/pkgsrc/rev/b742938611f8
branches:  trunk
changeset: 544047:b742938611f8
user:      ghen <ghen%pkgsrc.org@localhost>
date:      Sat Jul 05 12:04:38 2008 +0000

description:
Update seamonkey, seamonkey-bin and seamonkey-gtk1 to Seamonkey 1.1.10.

Security fixes in this version:

MFSA 2008-33 Crash and remote code execution in block reflow
MFSA 2008-32 Remote site run as local file via Windows URL shortcut
MFSA 2008-31 Peer-trusted certs can use alt names to spoof
MFSA 2008-30 File location URL in directory listings not escaped properly
MFSA 2008-29 Faulty .properties file results in uninitialized memory being used
MFSA 2008-28 Arbitrary socket connections with Java LiveConnect on Mac OS X
MFSA 2008-27 Arbitrary file upload via originalTarget and DOM Range
MFSA 2008-25 Arbitrary code execution in mozIJSSubScriptLoader.loadSubScript()
MFSA 2008-24 Chrome script loading from fastload file
MFSA 2008-23 Signed JAR tampering
MFSA 2008-22 XSS through JavaScript same-origin violation
MFSA 2008-21 Crashes with evidence of memory corruption (rv:1.8.1.15)
MFSA 2008-20 Crash in JavaScript garbage collector

For more info, see http://www.seamonkey-project.org/releases/seamonkey1.1.10/

diffstat:

 www/seamonkey-bin/Makefile              |   4 ++--
 www/seamonkey-bin/distinfo              |   8 ++++----
 www/seamonkey/Makefile-seamonkey.common |   4 ++--
 www/seamonkey/PLIST                     |   3 ++-
 www/seamonkey/distinfo                  |  14 +++++++-------
 www/seamonkey/patches/patch-af          |  17 ++---------------
 www/seamonkey/patches/patch-ap          |   6 +++---
 www/seamonkey/patches/patch-de          |  10 +++++-----
 8 files changed, 27 insertions(+), 39 deletions(-)

diffs (167 lines):

diff -r df612cbb5a30 -r b742938611f8 www/seamonkey-bin/Makefile
--- a/www/seamonkey-bin/Makefile        Sat Jul 05 12:02:54 2008 +0000
+++ b/www/seamonkey-bin/Makefile        Sat Jul 05 12:04:38 2008 +0000
@@ -1,7 +1,7 @@
-# $NetBSD: Makefile,v 1.22 2008/03/30 15:03:52 ghen Exp $
+# $NetBSD: Makefile,v 1.23 2008/07/05 12:04:38 ghen Exp $
 
 MOZILLA=               seamonkey
-MOZ_VER=               1.1.9
+MOZ_VER=               1.1.10
 MOZ_DISTVER=           ${MOZ_VER}
 
 HOMEPAGE=              http://www.mozilla.org/projects/seamonkey/
diff -r df612cbb5a30 -r b742938611f8 www/seamonkey-bin/distinfo
--- a/www/seamonkey-bin/distinfo        Sat Jul 05 12:02:54 2008 +0000
+++ b/www/seamonkey-bin/distinfo        Sat Jul 05 12:04:38 2008 +0000
@@ -1,5 +1,5 @@
-$NetBSD: distinfo,v 1.18 2008/03/30 15:03:52 ghen Exp $
+$NetBSD: distinfo,v 1.19 2008/07/05 12:04:38 ghen Exp $
 
-SHA1 (seamonkey/releases/1.1.9/seamonkey-1.1.9.en-US.linux-i686.tar.gz) = cc102f3f88f2112cfffc3e97cd34ed2e894d61d0
-RMD160 (seamonkey/releases/1.1.9/seamonkey-1.1.9.en-US.linux-i686.tar.gz) = 2d19da075aa2aed65aca11b31f2a226319a4eb72
-Size (seamonkey/releases/1.1.9/seamonkey-1.1.9.en-US.linux-i686.tar.gz) = 14795932 bytes
+SHA1 (seamonkey/releases/1.1.10/seamonkey-1.1.10.en-US.linux-i686.tar.gz) = 52c39d0e9a40b875e6722c58f25d42c0ddd76f9a
+RMD160 (seamonkey/releases/1.1.10/seamonkey-1.1.10.en-US.linux-i686.tar.gz) = d502505d42fe6b208ade59ec8c7f8028ee4834e9
+Size (seamonkey/releases/1.1.10/seamonkey-1.1.10.en-US.linux-i686.tar.gz) = 14805082 bytes
diff -r df612cbb5a30 -r b742938611f8 www/seamonkey/Makefile-seamonkey.common
--- a/www/seamonkey/Makefile-seamonkey.common   Sat Jul 05 12:02:54 2008 +0000
+++ b/www/seamonkey/Makefile-seamonkey.common   Sat Jul 05 12:04:38 2008 +0000
@@ -1,7 +1,7 @@
-# $NetBSD: Makefile-seamonkey.common,v 1.17 2008/03/30 15:02:40 ghen Exp $
+# $NetBSD: Makefile-seamonkey.common,v 1.18 2008/07/05 12:04:38 ghen Exp $
 
 MOZILLA_BIN=           seamonkey-bin
-MOZ_VER=               1.1.9
+MOZ_VER=               1.1.10
 EXTRACT_SUFX=          .tar.bz2
 DISTNAME=              seamonkey-${MOZ_DIST_VER}.source
 
diff -r df612cbb5a30 -r b742938611f8 www/seamonkey/PLIST
--- a/www/seamonkey/PLIST       Sat Jul 05 12:02:54 2008 +0000
+++ b/www/seamonkey/PLIST       Sat Jul 05 12:04:38 2008 +0000
@@ -1,4 +1,4 @@
-@comment $NetBSD: PLIST,v 1.14 2007/09/21 22:07:54 ghen Exp $
+@comment $NetBSD: PLIST,v 1.15 2008/07/05 12:04:38 ghen Exp $
 bin/${MOZILLA}
 @comment begin PROGRAMS
 lib/${MOZILLA}/${MOZILLA_BIN}
@@ -2315,6 +2315,7 @@
 include/${MOZILLA}/pipnss/nsITokenPasswordDialogs.h
 include/${MOZILLA}/pipnss/nsIUserCertPicker.h
 include/${MOZILLA}/pipnss/nsIX509Cert.h
+include/${MOZILLA}/pipnss/nsIX509Cert18Branch.h
 include/${MOZILLA}/pipnss/nsIX509Cert3.h
 include/${MOZILLA}/pipnss/nsIX509CertDB.h
 include/${MOZILLA}/pipnss/nsIX509CertDB2.h
diff -r df612cbb5a30 -r b742938611f8 www/seamonkey/distinfo
--- a/www/seamonkey/distinfo    Sat Jul 05 12:02:54 2008 +0000
+++ b/www/seamonkey/distinfo    Sat Jul 05 12:04:38 2008 +0000
@@ -1,14 +1,14 @@
-$NetBSD: distinfo,v 1.30 2008/05/19 10:43:02 tnn Exp $
+$NetBSD: distinfo,v 1.31 2008/07/05 12:04:38 ghen Exp $
 
-SHA1 (seamonkey-1.1.9.source.tar.bz2) = e33d78a005d01f982e45db55034d776fda419e25
-RMD160 (seamonkey-1.1.9.source.tar.bz2) = 30ae304710fae33f83bdbb57b1d9092eb6ed8daf
-Size (seamonkey-1.1.9.source.tar.bz2) = 35273677 bytes
+SHA1 (seamonkey-1.1.10.source.tar.bz2) = b07b2baa95abfad282e769f734e14004300634ec
+RMD160 (seamonkey-1.1.10.source.tar.bz2) = be23ea2022b26f43e579aba32b007b0641445890
+Size (seamonkey-1.1.10.source.tar.bz2) = 38059752 bytes
 SHA1 (patch-aa) = 2d117311991c4c71803f3c446334d7b6f1e1067a
 SHA1 (patch-ab) = b83dc786559d010f9bbb1adde697975166e0735e
 SHA1 (patch-ac) = 393920aabf9476b668510a88af041d9a54c6019d
 SHA1 (patch-ad) = 2210b695a2eedefb82c16698a51f4f0f6b2e53e4
 SHA1 (patch-ae) = f3c8ffcdfc8c0d5cc75413602c97c731721d751e
-SHA1 (patch-af) = 4844013ad49c77b87be7c30931ca786f246b40f3
+SHA1 (patch-af) = 892d660421a311dc31043afaa969f12cef540f85
 SHA1 (patch-ag) = eaebefa81d03b2ebc8a32465f59889d92944d750
 SHA1 (patch-ah) = 8f92f4294ead04ddc5b719ff66b4aada912dcc01
 SHA1 (patch-ai) = 189aa46f116e424c23368e1c7fbc6c56dd389954
@@ -17,7 +17,7 @@
 SHA1 (patch-al) = d916f38de2fa0ca1993ec75c457fccc60ee6d612
 SHA1 (patch-an) = 99ac2da44322db96f8d65fbfdb380727b9da96fe
 SHA1 (patch-ao) = 617d232bd335bc988388f2004ca919c829e371da
-SHA1 (patch-ap) = b696056ad90e539cb537e95b163385a48c8ea2cc
+SHA1 (patch-ap) = 088124f118b44a41834eb734c555828b93772696
 SHA1 (patch-aq) = 29183e61d6b1a38853151426c2d4ffe45efd9c43
 SHA1 (patch-aw) = db73e21e67dc4200312285973faaaed308ea436e
 SHA1 (patch-ax) = 2d5cfeef594ed34249828b6d7c222b17901a4164
@@ -48,7 +48,7 @@
 SHA1 (patch-db) = f10187cf9de4466e49a967b79875eb01c5afd69f
 SHA1 (patch-dc) = ba7b06f04460d4966e115a9ffdeafc1ebf555972
 SHA1 (patch-dd) = de9d705fdc3cb9879a19d58dfd170d104ca379f7
-SHA1 (patch-de) = 1d845fd60ecd85554fa82f6c5f3cc7edc7d377a5
+SHA1 (patch-de) = 909a9226be4141da96a1fa749d4e539a37307486
 SHA1 (patch-df) = 17912d183f754ab6661d2be8092e6a07d142632b
 SHA1 (patch-dh) = 7592a6238acd5ef6e802d32103c897acb576825a
 SHA1 (patch-dj) = 70360dffb20dd1029866d2e81899d003c9e17473
diff -r df612cbb5a30 -r b742938611f8 www/seamonkey/patches/patch-af
--- a/www/seamonkey/patches/patch-af    Sat Jul 05 12:02:54 2008 +0000
+++ b/www/seamonkey/patches/patch-af    Sat Jul 05 12:04:38 2008 +0000
@@ -1,6 +1,6 @@
-$NetBSD: patch-af,v 1.1.1.1 2006/03/30 19:15:47 ghen Exp $
+$NetBSD: patch-af,v 1.2 2008/07/05 12:04:38 ghen Exp $
 
---- security/nss/lib/freebl/unix_rand.c.orig   2005-10-11 01:22:50.000000000 +0200
+--- security/nss/lib/freebl/unix_rand.c.orig   2008-06-16 00:22:09.000000000 +0200
 +++ security/nss/lib/freebl/unix_rand.c
 @@ -35,6 +35,7 @@
   * ***** END LICENSE BLOCK ***** */
@@ -10,16 +10,3 @@
  #include <string.h>
  #include <signal.h>
  #include <unistd.h>
-@@ -694,7 +695,11 @@ safe_popen(char *cmd)
-       /* dup write-side of pipe to stderr and stdout */
-       if (p[1] != 1) dup2(p[1], 1);
-       if (p[1] != 2) dup2(p[1], 2);
--      close(0);
-+      fd = open("/dev/null", O_RDONLY);
-+      if (fd != 0) {
-+          dup2(fd, 0);
-+          close(fd);
-+      }
-         {
-             int ndesc = getdtablesize();
-             for (fd = PR_MIN(65536, ndesc); --fd > 2; close(fd));
diff -r df612cbb5a30 -r b742938611f8 www/seamonkey/patches/patch-ap
--- a/www/seamonkey/patches/patch-ap    Sat Jul 05 12:02:54 2008 +0000
+++ b/www/seamonkey/patches/patch-ap    Sat Jul 05 12:04:38 2008 +0000
@@ -1,6 +1,6 @@
-$NetBSD: patch-ap,v 1.4 2007/01/20 10:54:44 ghen Exp $
+$NetBSD: patch-ap,v 1.5 2008/07/05 12:04:38 ghen Exp $
 
---- security/coreconf/command.mk.orig  2006-12-22 14:48:07.000000000 +0100
+--- security/coreconf/command.mk.orig  2008-06-16 00:22:15.000000000 +0200
 +++ security/coreconf/command.mk
 @@ -45,7 +45,7 @@ ASFLAGS      += $(CFLAGS)
  CCF           = $(CC) $(CFLAGS)
@@ -9,5 +9,5 @@
 -CFLAGS        = $(OPTIMIZER) $(OS_CFLAGS) $(XP_DEFINE) $(DEFINES) $(INCLUDES) \
 +CFLAGS       += $(OS_CFLAGS) $(XP_DEFINE) $(DEFINES) $(INCLUDES) \
                $(XCFLAGS)
+ PERL          = perl
  RANLIB        = echo
- TAR           = /bin/tar
diff -r df612cbb5a30 -r b742938611f8 www/seamonkey/patches/patch-de
--- a/www/seamonkey/patches/patch-de    Sat Jul 05 12:02:54 2008 +0000
+++ b/www/seamonkey/patches/patch-de    Sat Jul 05 12:04:38 2008 +0000
@@ -1,13 +1,13 @@
-$NetBSD: patch-de,v 1.1 2007/01/30 14:34:34 joerg Exp $
+$NetBSD: patch-de,v 1.2 2008/07/05 12:04:38 ghen Exp $
 
---- security/nss/lib/freebl/Makefile.orig      2006-12-06 18:01:13.000000000 +0000
+--- security/nss/lib/freebl/Makefile.orig      2008-06-16 00:22:09.000000000 +0200
 +++ security/nss/lib/freebl/Makefile
-@@ -192,7 +192,7 @@ endif
+@@ -194,7 +194,7 @@ endif
  # to bind the blapi function references in FREEBLVector vector
  # (ldvector.c) to the blapi functions defined in the freebl
  # shared libraries.
--ifeq (,$(filter-out BSD_OS FreeBSD Linux NetBSD, $(OS_TARGET)))
-+ifeq (,$(filter-out BSD_OS DragonFly FreeBSD Linux NetBSD, $(OS_TARGET)))
+-ifeq (,$(filter-out BSD_OS FreeBSD Linux NetBSD OpenBSD, $(OS_TARGET)))
++ifeq (,$(filter-out BSD_OS DragonFly FreeBSD Linux NetBSD OpenBSD, $(OS_TARGET)))
      MKSHLIB += -Wl,-Bsymbolic
  endif
  



Home | Main Index | Thread Index | Old Index