Subject: pkg/26594: update mozilla and mozilla-gtk2 to 1.7.2
To: None <gnats-bugs@gnats.NetBSD.org>
From: None <hira@po6.nsk.ne.jp>
List: pkgsrc-bugs
Date: 08/08/2004 22:55:17
>Number:         26594
>Category:       pkg
>Synopsis:       update mozilla and mozilla-gtk2 to 1.7.2
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    pkg-manager
>State:          open
>Class:          change-request
>Submitter-Id:   net
>Arrival-Date:   Sun Aug 08 14:07:00 UTC 2004
>Closed-Date:
>Last-Modified:
>Originator:     Kouichirou Hiratsuka
>Release:        NetBSD 2.0G
>Organization:
>Environment:
System: NetBSD firefly.localdomain 2.0G NetBSD 2.0G (FIREFLY.MP) #51: Sun Aug 8 18:03:10 JST 2004 root@firefly.localdomain:/usr/src/sys/arch/i386/compile/FIREFLY.MP i386
Architecture: i386
Machine: i386
>Description:
	Mozilla 1.7.2 was released on Aug. 4.  Three security vulnerabilities
	have been fixed.

	- Importing false CA certificate leading to error -8182 (perm DoS),
	  especially exploitable by email (#249004)
	- lock icon and certificates spoofable with onunload document.write
	  (#253121)
	- new libpng buffer overflow vulnerabilities (#251381)

>How-To-Repeat:
	
>Fix:
Index: mozilla/Makefile
===================================================================
RCS file: /cvs/cvsroot/pkgsrc/www/mozilla/Makefile,v
retrieving revision 1.135
diff -u -r1.135 Makefile
--- mozilla/Makefile	5 Jul 2004 14:22:42 -0000	1.135
+++ mozilla/Makefile	7 Aug 2004 21:41:54 -0000
@@ -2,8 +2,7 @@
 
 MOZILLA=	mozilla
 MOZILLA_BIN=	mozilla-bin
-MOZ_VER=	1.7
-PKGREVISION=	1
+MOZ_VER=	1.7.2
 EXTRACT_SUFX=	.tar.bz2
 
 DISTFILES=	${DISTNAME}${EXTRACT_SUFX}
Index: mozilla/distinfo
===================================================================
RCS file: /cvs/cvsroot/pkgsrc/www/mozilla/distinfo,v
retrieving revision 1.61
diff -u -r1.61 distinfo
--- mozilla/distinfo	26 Jul 2004 23:36:01 -0000	1.61
+++ mozilla/distinfo	8 Aug 2004 11:03:44 -0000
@@ -1,7 +1,7 @@
 $NetBSD: distinfo,v 1.61 2004/07/26 23:36:01 taya Exp $
 
-SHA1 (mozilla-source-1.7.tar.bz2) = 52b8ab9248a8f4ed5763d7715f4fa18bda8123cf
-Size (mozilla-source-1.7.tar.bz2) = 35174502 bytes
+SHA1 (mozilla-source-1.7.2.tar.bz2) = 75c6f68d198e2fe0b7be525af6d458cc07c7d48d
+Size (mozilla-source-1.7.2.tar.bz2) = 34438800 bytes
 SHA1 (patch-aa) = be62070f062e8ae13f06bd7b3f4f0d4a9ee67bef
 SHA1 (patch-ab) = 334a1e79d63d045dafb50b82ea192b311b55e7d5
 SHA1 (patch-ac) = 32aa4b92eea19aca07077a292cb759d074026642
Index: mozilla-gtk2/Makefile
===================================================================
RCS file: /cvs/cvsroot/pkgsrc/www/mozilla-gtk2/Makefile,v
retrieving revision 1.10
diff -u -r1.10 Makefile
--- mozilla-gtk2/Makefile	5 Jul 2004 14:23:53 -0000	1.10
+++ mozilla-gtk2/Makefile	7 Aug 2004 20:30:57 -0000
@@ -2,8 +2,7 @@
 
 MOZILLA=	mozilla-gtk2
 MOZILLA_BIN=	mozilla-bin
-MOZ_VER=	1.7
-PKGREVISION=	1
+MOZ_VER=	1.7.2
 EXTRACT_SUFX=	.tar.bz2
 
 DISTFILES=	${DISTNAME}${EXTRACT_SUFX}

>Release-Note:
>Audit-Trail:
>Unformatted: