Hello community, here is the log from the commit of package MozillaThunderbird checked in at Mon Sep 15 12:18:40 CEST 2008. -------- --- MozillaThunderbird/MozillaThunderbird.changes 2008-07-23 18:01:12.000000000 +0200 +++ /mounts/work_src_done/STABLE/MozillaThunderbird/MozillaThunderbird.changes 2008-09-11 21:37:35.924677000 +0200 @@ -1,0 +2,16 @@ +Thu Sep 11 21:34:40 CEST 2008 - mauro@suse.de + +- Update to 2.0.0.16 (fixed bnc#417869), fixes: + + MFSA 2008-34 Remote code execution by overflowing CSS + reference counter + + MFSA 2008-33 Crash and remote code execution in block reflow + + MFSA 2008-31 Peer-trusted certs can use alt names to spoof + + MFSA 2008-29 Faulty .properties file results in uninitialized + memory being used + + MFSA 2008-26 Buffer length checks in MIME processing + + MFSA 2008-25 Arbitrary code execution in + mozIJSSubScriptLoader.loadSubScript() + + MFSA 2008-24 Chrome script loading from fastload file + + MFSA 2008-21 Crashes with evidence of memory corruption (rv:1.8.1.15) + +------------------------------------------------------------------- Old: ---- enigmail-0.95.6.tar.gz l10n-2.0.0.14.tar.bz2 mailredirect-0.7.4.xpi mozilla-gcc4.3-fixes.patch thunderbird-2.0.0.14-source.tar.bz2 unused-includes.patch New: ---- enigmail-0.95.7.tar.bz2 l10n-2.0.0.16.tar.bz2 mailredirect-0.7.5.xpi MozillaThunderbird-2.0.0.16-rpmlintrc thunderbird-2.0.0.16-source.tar.bz2 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ MozillaThunderbird.spec ++++++ --- /var/tmp/diff_new_pack.KSl371/_old 2008-09-15 12:15:28.000000000 +0200 +++ /var/tmp/diff_new_pack.KSl371/_new 2008-09-15 12:15:28.000000000 +0200 @@ -1,10 +1,17 @@ # -# spec file for package MozillaThunderbird (Version 2.0.0.14) +# spec file for package MozillaThunderbird (Version 2.0.0.16) # # Copyright (c) 2008 SUSE LINUX Products GmbH, Nuernberg, Germany. -# This file and all modifications and additions to the pristine -# package are under the same license as the package itself. # +# All modifications and additions to the file contributed by third parties +# remain the property of their copyright owners, unless otherwise agreed +# upon. The license for this file, and modifications and additions to the +# file, is the same license as for the pristine package itself (unless the +# license for the pristine package is not an Open Source License, in which +# case the license is the MIT License). An "Open Source License" is a +# license that conforms to the Open Source Definition (Version 1.9) +# published by the Open Source Initiative. + # Please submit bugfixes or comments via http://bugs.opensuse.org/ # @@ -13,8 +20,8 @@ Name: MozillaThunderbird BuildRequires: fdupes gcc-c++ libgnomeui-devel libidl-devel mozilla-nss-devel orbit-devel unzip update-desktop-files zip License: GPL v2 or later; LGPL v2.1 or later; MOZILLA PUBLIC LICENSE (MPL/NPL) -Version: 2.0.0.14 -Release: 11 +Version: 2.0.0.16 +Release: 1 Summary: The Stand-Alone Mozilla Mail Component Url: http://www.mozilla.org/products/thunderbird/ Group: Productivity/Networking/Email/Clients @@ -23,13 +30,14 @@ Source2: add-plugins.sh.in Source3: mozilla.sh.in Source4: l10n-%{version}.tar.bz2 -Source5: mailredirect-0.7.4.xpi +Source5: mailredirect-0.7.5.xpi Source6: suse-default-prefs.js -Source9: enigmail-0.95.6.tar.gz +Source9: enigmail-0.95.7.tar.bz2 Source11: enigmail.manifest +Source12: %{name}-%{version}-rpmlintrc Patch1: replytolist.patch Patch2: thunderbird-appname.patch -Patch3: mozilla-gcc4.3-fixes.patch +#Patch3: mozilla-gcc4.3-fixes.patch Patch4: locale.patch Patch5: abuild.patch Patch6: nspr-prdtoa.patch @@ -50,7 +58,7 @@ Patch27: thunderbird-1.5.0.8-uninitalized-vars-232305.patch #Patch28: thunderbird-gcc4.3-fixes.patch Patch29: visibility.patch -Patch30: unused-includes.patch +#Patch30: unused-includes.patch BuildRoot: %{_tmppath}/%{name}-%{version}-build PreReq: libstdc++ fileutils textutils /bin/sh %if %suse_version > 1000 @@ -78,7 +86,7 @@ BuildRequires: mozilla-nss-devel %endif %define _unpackaged_files_terminate_build 0 -%define releasedate 2008042100 +%define releasedate 2008072000 %define progname thunderbird %define progdir %{_prefix}/%_lib/thunderbird %define my_provides /tmp/my-provides @@ -115,7 +123,7 @@ %package translations License: GPL v2 or later; LGPL v2.1 or later; MOZILLA PUBLIC LICENSE (MPL/NPL) Summary: Translations of MozillaThunderbird -Provides: locale(MozillaThunderbird:af;be;bg;ca;cs;da;de;el;en_GB;es_AR;es_ES;eu;fi;fr;ga_IE;he;hu;it;ja;ko;lt;mk;nb_NO;nl;nn_NO;pa_IN;pl;pt_BR;pt_PT;ru;sk;sl;sv_SE;tr;uk;zh_CN;zh_TW) +Provides: locale(MozillaThunderbird:be;bg;ca;cs;da;de;el;en_GB;es_AR;es_ES;eu;fi;fr;ga_IE;hu;it;ja;ko;lt;mk;nb_NO;nl;nn_NO;pa_IN;pl;pt_BR;pt_PT;ru;sk;sl;sv_SE;tr;zh_CN;zh_TW) Group: Productivity/Networking/Email/Clients PreReq: %{name} = %{version} @@ -164,7 +172,7 @@ cd $RPM_BUILD_DIR/mozilla %patch1 %patch2 -%patch3 +#%patch3 %patch4 %patch5 %patch6 @@ -183,7 +191,7 @@ %patch26 %patch27 -p0 # %patch28 -p1 -%patch30 +#%patch30 %build export MOZ_BUILD_DATE=%{releasedate} @@ -672,6 +680,19 @@ %{_bindir}/thunderbird-config %changelog +* Thu Sep 11 2008 mauro@suse.de +- Update to 2.0.0.16 (fixed bnc#417869), fixes: + + MFSA 2008-34 Remote code execution by overflowing CSS + reference counter + + MFSA 2008-33 Crash and remote code execution in block reflow + + MFSA 2008-31 Peer-trusted certs can use alt names to spoof + + MFSA 2008-29 Faulty .properties file results in uninitialized + memory being used + + MFSA 2008-26 Buffer length checks in MIME processing + + MFSA 2008-25 Arbitrary code execution in + mozIJSSubScriptLoader.loadSubScript() + + MFSA 2008-24 Chrome script loading from fastload file + + MFSA 2008-21 Crashes with evidence of memory corruption (rv:1.8.1.15) * Wed Jul 23 2008 schwab@suse.de - Remove unused includes. * Tue Jun 24 2008 maw@suse.de ++++++ l10n-2.0.0.14.tar.bz2 -> l10n-2.0.0.16.tar.bz2 ++++++ MozillaThunderbird/l10n-2.0.0.14.tar.bz2 /mounts/work_src_done/STABLE/MozillaThunderbird/l10n-2.0.0.16.tar.bz2 differ: byte 11, line 1 ++++++ thunderbird-2.0.0.14-source.tar.bz2 -> thunderbird-2.0.0.16-source.tar.bz2 ++++++ MozillaThunderbird/thunderbird-2.0.0.14-source.tar.bz2 /mounts/work_src_done/STABLE/MozillaThunderbird/thunderbird-2.0.0.16-source.tar.bz2 differ: byte 11, line 1 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Remember to have fun... --------------------------------------------------------------------- To unsubscribe, e-mail: opensuse-commit+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-commit+help@opensuse.org