-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 05 Aug 2010 13:55:35 -0400 Source: icedove Binary: icedove icedove-dev icedove-dbg Architecture: source amd64 Version: 3.0.6-1 Distribution: unstable Urgency: low Maintainer: Alexander Sack <asac@debian.org> Changed-By: Christoph Goehre <chris@sigxcpu.org> Description: icedove - mail/news client with RSS and integrated spam filter support icedove-dbg - Debug Symbols for Icedove icedove-dev - Development files for Icedove Closes: 580297 Changes: icedove (3.0.6-1) unstable; urgency=low . * New Upstream Version - MFSA 2010-34 aka CVE-2010-1211, CVE-2010-1212: Miscellaneous memory safety hazards (rv:1.9.2.7/ 1.9.1.11) - MFSA 2010-39 aka CVE-2010-2752: nsCSSValue::Array index integer overflow - MFSA 2010-40 aka CVE-2010-2753: nsTreeSelection dangling pointer remote code execution vulnerability - MFSA 2010-41 aka CVE-2010-1205: Remote code execution using malformed PNG image - MFSA 2010-42 aka CVE-2010-1213: Cross-origin data disclosure via Web Workers and importScripts - MFSA 2010-46 aka CVE-2010-0654: Cross-domain data theft using CSS - MFSA 2010-47 aka CVE-2010-2754: Cross-origin data leakage from script filename in error messages * [7efdfaf] rebuild patch queue from patch-queue branch added patches: - 0054-Use-syscall-for-mmap-and-munmap-and-disable-ncpus-in.patch (Closes: #580297) - 0055-Ignore-system-libjpeg-libpng-and-zlib-version-checki.patch - 0056-Disable-APNG-support-when-system-libpng-doesn-t-supp.patch modified patches: - 0012-Support-building-on-GNU-kFreeBSD-and-GNU-Hurd.patch * [ceb5c15] bump up standards version to 3.9.1 * [fd8dd2f] lintian: downgrade Conflicts to Breaks * [4046823] build against system libpng Checksums-Sha1: b74693cc1105e496833fa73dcd64f65983a3f609 1845 icedove_3.0.6-1.dsc 179436956393a9f79275a112bfc915469d226939 51873290 icedove_3.0.6.orig.tar.bz2 2af123d9cb70a9f8ffc5d3d19815603729fa0ed5 363600 icedove_3.0.6-1.debian.tar.gz 67e018fa06150818e4b765a8a8acbb4714ad1bb3 12463150 icedove_3.0.6-1_amd64.deb 1b85b5781b95c442cf3ca7c814360f577ea27e61 5748894 icedove-dev_3.0.6-1_amd64.deb 88f2959267d130c3f21cf164c7c642308ef7568c 67804846 icedove-dbg_3.0.6-1_amd64.deb Checksums-Sha256: b9d2742a5d23164bc5dcd0e086a92cfc016dfe5beea001e95cf5fdf449408647 1845 icedove_3.0.6-1.dsc 69b6bec813bffb3de2963a22031a65dd33ed9c51bca7a06630009b7b34684d14 51873290 icedove_3.0.6.orig.tar.bz2 d433ef2bd01fb38be092b33aa1120be81a2b6cd6c0d1971d6253137330e83b36 363600 icedove_3.0.6-1.debian.tar.gz 4b8beee8fd6e48a297e6d220ecf23247630d8ab17308c1feb36cf977f4a0571c 12463150 icedove_3.0.6-1_amd64.deb e490d42d5bda823cac8f190a976ab81c8fd204546bacfa09d95d1b1cabd10ac8 5748894 icedove-dev_3.0.6-1_amd64.deb 78dfe188d05fc8b6bee205995c27b2758afb8fc039a2bd994e0af7ef1bb16835 67804846 icedove-dbg_3.0.6-1_amd64.deb Files: df2707d33c00b44bbc4ca2d0f6faba85 1845 web optional icedove_3.0.6-1.dsc 0ebb9852a2e3e4e78b95793869973d10 51873290 web optional icedove_3.0.6.orig.tar.bz2 d11ed1a37dfbaf0838443a5827a86c39 363600 web optional icedove_3.0.6-1.debian.tar.gz 6bb4cd050a4dd8819e87341307ce2166 12463150 mail optional icedove_3.0.6-1_amd64.deb 9dadc791686fab05783d5bbb20b37c28 5748894 mail optional icedove-dev_3.0.6-1_amd64.deb 2eaf7cfc2a059f057608220dd799e979 67804846 debug extra icedove-dbg_3.0.6-1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkxbB4gACgkQaT2DDHtihbdUAACfY+EuJYYDKoCEOKo9TTsOGo9R d2wAoKlA1mtX8z1VMVQ6gvbpCGsvbg++ =zwa5 -----END PGP SIGNATURE----- Accepted: icedove-dbg_3.0.6-1_amd64.deb to main/i/icedove/icedove-dbg_3.0.6-1_amd64.deb icedove-dev_3.0.6-1_amd64.deb to main/i/icedove/icedove-dev_3.0.6-1_amd64.deb icedove_3.0.6-1.debian.tar.gz to main/i/icedove/icedove_3.0.6-1.debian.tar.gz icedove_3.0.6-1.dsc to main/i/icedove/icedove_3.0.6-1.dsc icedove_3.0.6-1_amd64.deb to main/i/icedove/icedove_3.0.6-1_amd64.deb icedove_3.0.6.orig.tar.bz2 to main/i/icedove/icedove_3.0.6.orig.tar.bz2