-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 13 Aug 2010 12:18:21 +0200 Source: icedove Binary: icedove icedove-dev icedove-dbg Architecture: source amd64 Version: 3.1.2-1 Distribution: experimental Urgency: low Maintainer: Alexander Sack <asac@debian.org> Changed-By: Christoph Goehre <chris@sigxcpu.org> Description: icedove - mail/news client with RSS and integrated spam filter support icedove-dbg - Debug Symbols for Icedove icedove-dev - Development files for Icedove Closes: 589476 589666 591899 Changes: icedove (3.1.2-1) experimental; urgency=low . * New Upstream Version (Closes: #589666, #591899) - MFSA 2010-34 aka CVE-2010-1211, CVE-2010-1212: Miscellaneous memory safety hazards (rv:1.9.2.7/ 1.9.1.11) - MFSA 2010-38 aka CVE-2010-1215: Arbitrary code execution using SJOW and fast native function - MFSA 2010-39 aka CVE-2010-2752: nsCSSValue::Array index integer overflow - MFSA 2010-40 aka CVE-2010-2753: nsTreeSelection dangling pointer remote code execution vulnerability - MFSA 2010-41 aka CVE-2010-1205: Remote code execution using malformed PNG image - MFSA 2010-42 aka CVE-2010-1213: Cross-origin data disclosure via Web Workers and importScripts - MFSA 2010-43 aka CVE-2010-1207: Same-origin bypass using canvas context - MFSA 2010-44 aka CVE-2010-1210: Characters mapped to U+FFFD in 8 bit encodings cause subsequent character to vanish - MFSA 2010-46 aka CVE-2010-0654: Cross-domain data theft using CSS - MFSA 2010-47 aka CVE-2010-2754: Cross-origin data leakage from script filename in error messages * [6b9976e] rebuild patch queue from patch-queue branch modified patches: - 0010-Support-building-on-GNU-kFreeBSD-and-GNU-Hurd.patch - 0015-Don-t-register-plugins-if-the-MOZILLA_DISABLE_PLUGIN.patch - 0018-Work-around-FTBFS-on-mips-by-disabling-TLS-support.patch - 0034-Fix-compiler-errors-with-g-4.4-with-std-gnu-0x.patch - 0045-Expose-fullpath-from-nsIPluginTag.patch - 0047-Use-syscall-for-mmap-and-munmap-and-disable-ncpus-in.patch - 0050-Set-javascript.options.showInConsole.patch - 0057-Allow-to-build-against-system-libffi.patch - 0058-Ignore-system-libjpeg-libpng-and-zlib-version-checki.patch - 0059-Disable-APNG-support-when-system-libpng-doesn-t-supp.patch * [16b0e7e] fix FTBFS on kfreebsd-* and hurd-i386 by passing --disable-necko-wifi to configure (Closes: #589476) * [15a02c7] bump up standards version to 3.9.1 Checksums-Sha1: df45154930be0ce2b9580c4be60cea87fba81ef7 1881 icedove_3.1.2-1.dsc 85b5e439965963fb6a1cc4aef6c68d7b1ddfff1c 58793076 icedove_3.1.2.orig.tar.bz2 e685b258bce8876fee043186b1b5464ce6446d36 456648 icedove_3.1.2-1.debian.tar.gz 3c4e52c32230937bca0d647137319f13e3fca47c 13184976 icedove_3.1.2-1_amd64.deb ad454de3a603ab46831728f804811f8967a09b93 5464644 icedove-dev_3.1.2-1_amd64.deb fbe91c01f61765b827847f6659951c6247a01d95 66828390 icedove-dbg_3.1.2-1_amd64.deb Checksums-Sha256: c67d0b64527e46ea55d58618a96008b0c9424ee9be804c93b4b7fc0869dbb588 1881 icedove_3.1.2-1.dsc 825f2e57d393ac81a7dc6afd43fe86f063889c884748acc6858e325594d8ac96 58793076 icedove_3.1.2.orig.tar.bz2 791f1b8c46723d49e2415428f9067417d001565e7ab666e0c1543d6b5c2f9dcc 456648 icedove_3.1.2-1.debian.tar.gz 3e7909f7f303937c10784d996c68b973614527e13346a927a44b56f85aaa2d57 13184976 icedove_3.1.2-1_amd64.deb b430a95888afb9d95d68614fb6acd8c99377ff8cf5ec56d0f5e0c36f57264981 5464644 icedove-dev_3.1.2-1_amd64.deb 3001f496b206b25d903cb59940222f523cbb08e1831d9a6f91fff763855fa749 66828390 icedove-dbg_3.1.2-1_amd64.deb Files: b558469d86e24edb2c463d146e5ef635 1881 web optional icedove_3.1.2-1.dsc 1f428a69243bb7cb49353e473937d2b0 58793076 web optional icedove_3.1.2.orig.tar.bz2 9d83db7c48e1c5b2658f1edd53d19742 456648 web optional icedove_3.1.2-1.debian.tar.gz bbcbc601db1dd3c684a4026417d030ec 13184976 mail optional icedove_3.1.2-1_amd64.deb bb253f0fb74f7934451fa54c411613fe 5464644 mail optional icedove-dev_3.1.2-1_amd64.deb 55450cd513ff35392d2f5731aeae8613 66828390 debug extra icedove-dbg_3.1.2-1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkxlMvoACgkQaT2DDHtihbcW1ACgrDpuii3Z8iFljLf3nDGr/bGi OTIAn3xW7Ydfds7rWz7zhSutNqOnC3cv =Mrq7 -----END PGP SIGNATURE----- Accepted: icedove-dbg_3.1.2-1_amd64.deb to main/i/icedove/icedove-dbg_3.1.2-1_amd64.deb icedove-dev_3.1.2-1_amd64.deb to main/i/icedove/icedove-dev_3.1.2-1_amd64.deb icedove_3.1.2-1.debian.tar.gz to main/i/icedove/icedove_3.1.2-1.debian.tar.gz icedove_3.1.2-1.dsc to main/i/icedove/icedove_3.1.2-1.dsc icedove_3.1.2-1_amd64.deb to main/i/icedove/icedove_3.1.2-1_amd64.deb icedove_3.1.2.orig.tar.bz2 to main/i/icedove/icedove_3.1.2.orig.tar.bz2