Subject: CVS commit: pkgsrc/www
To: None <pkgsrc-changes@NetBSD.org>
From: Shin'ichiro TAYA <taya@netbsd.org>
List: pkgsrc-changes
Date: 03/24/2005 14:08:29
Module Name:	pkgsrc
Committed By:	taya
Date:		Thu Mar 24 14:08:29 UTC 2005

Modified Files:
	pkgsrc/www/mozilla: Makefile PLIST buildlink3.mk distinfo
	pkgsrc/www/mozilla-gtk2: Makefile PLIST buildlink3.mk

Log Message:
Update mozilla & mozilla-gtk2 to 1.7.6

This is a security fix release.
Fixed bugs are follows.

MFSA 2005-32  Drag and drop loading of privileged XUL
MFSA 2005-30 GIF heap overflow parsing Netscape extension 2
MFSA 2005-29 Internationalized Domain Name (IDN) homograph spoofing
MFSA 2005-28 Unsafe /tmp/plugtmp directory exploitable to erase user's files
MFSA 2005-27 Plugins can be used to load privileged content
MFSA 2005-26 Cross-site scripting by dropping javascript: link on tab
MFSA 2005-25 Image drag and drop executable spoofing
MFSA 2005-24 HTTP auth prompt tab spoofing
MFSA 2005-23 Download dialog source spoofing
MFSA 2005-21 Overwrite arbitrary files downloading .lnk twice
MFSA 2005-20 XSLT can include stylesheets from arbitrary hosts
MFSA 2005-18 Memory overwrite in string library
MFSA 2005-17 Install source spoofing with user:pass@host
MFSA 2005-16 Spoofing download and security dialogs with overlapping windows
MFSA 2005-15 Heap overflow possible in UTF8 to Unicode conversion
MFSA 2005-14 SSL "secure site" indicator spoofing
MFSA 2005-13 Window Injection Spoofing

see changelog for detail.
http://www.mozilla.org/releases/mozilla1.7.6/changelog.html


To generate a diff of this commit:
cvs rdiff -r1.141 -r1.142 pkgsrc/www/mozilla/Makefile
cvs rdiff -r1.15 -r1.16 pkgsrc/www/mozilla/PLIST
cvs rdiff -r1.7 -r1.8 pkgsrc/www/mozilla/buildlink3.mk
cvs rdiff -r1.72 -r1.73 pkgsrc/www/mozilla/distinfo
cvs rdiff -r1.16 -r1.17 pkgsrc/www/mozilla-gtk2/Makefile
cvs rdiff -r1.5 -r1.6 pkgsrc/www/mozilla-gtk2/PLIST \
    pkgsrc/www/mozilla-gtk2/buildlink3.mk

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.