-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 22 Sep 2012 18:44:16 -0400 Source: icedove Binary: icedove icedove-dev icedove-dbg Architecture: source amd64 Version: 3.0.11-1+squeeze13 Distribution: stable-security Urgency: high Maintainer: Alexander Sack <asac@debian.org> Changed-By: Christoph Goehre <chris@sigxcpu.org> Description: icedove - mail/news client with RSS and integrated spam filter support icedove-dbg - Debug Symbols for Icedove icedove-dev - Development files for Icedove Changes: icedove (3.0.11-1+squeeze13) stable-security; urgency=high . * [9738634] backported patches from xulrunner fixes mfsa2012-{57,58,63,65,70} - MFSA 2012-57 aka CVE-2012-1970: Miscellaneous memory safety hazards (rv:15.0/ rv:10.0.7) - MFSA 2012-58 aka CVE-2012-1972, CVE-2012-1973, CVE-2012-1974, CVE-2012-1975, CVE-2012-1976, CVE-2012-3959, CVE-2012-3962: Use-after-free issues found using Address Sanitizer - MFSA 2012-63 aka CVE-2012-3969: SVG buffer overflow and use-after-free issues - MFSA 2012-65 aka CVE-2012-3972: Out-of-bounds read in format-number in XSLT - MFSA 2012-70 aka CVE-2012-3978: Location object security checks bypassed by chrome code Checksums-Sha1: 1e06bdd98c3b9ce876d26224eb292e3b141339b8 2532 icedove_3.0.11-1+squeeze13.dsc cf7d32781ca25220228a65c73ca96241deaa708b 535282 icedove_3.0.11-1+squeeze13.debian.tar.gz 94962583b34315ba5e53e81b0356f84c20f2b851 12535722 icedove_3.0.11-1+squeeze13_amd64.deb 80064303c72c39fc112687b238363b7c75fc9a20 5742228 icedove-dev_3.0.11-1+squeeze13_amd64.deb 80a581ddf69dcd29a4e0baeca9b538f30a548d8d 68346034 icedove-dbg_3.0.11-1+squeeze13_amd64.deb Checksums-Sha256: dfb5a478e0752ea1c7f79de3a78d6830e1a7cf9d6a87a0037cbca1124f25df1b 2532 icedove_3.0.11-1+squeeze13.dsc da965daf8e13d0b93f259fbe95b851783c0425fb40215327d56ee16ed78c2e92 535282 icedove_3.0.11-1+squeeze13.debian.tar.gz 7f0570c7f636a0a5514845c7cf79554d8e71a1c6f24865e1346606b4a5653475 12535722 icedove_3.0.11-1+squeeze13_amd64.deb 9559381e0d66f8e3c98b9058e4ed1f18b7f508e7b9b1d85a54e5de1722b5cf9b 5742228 icedove-dev_3.0.11-1+squeeze13_amd64.deb 093e0281bb0cd5739f513a2cdeb68ad075d7349b7e1ebd4ca5bee6d1c81d1c45 68346034 icedove-dbg_3.0.11-1+squeeze13_amd64.deb Files: aa4f02c5bdda00594abccb2d4d1ded4f 2532 web optional icedove_3.0.11-1+squeeze13.dsc 7e5bcd980a0d6f84350709a2ce2840e9 535282 web optional icedove_3.0.11-1+squeeze13.debian.tar.gz c683017271a2c6d8a53788029dfdbfa9 12535722 mail optional icedove_3.0.11-1+squeeze13_amd64.deb ed6067868d5c0558bad697bed4056bd2 5742228 mail optional icedove-dev_3.0.11-1+squeeze13_amd64.deb 663407f83a6b4fd4f1beb0c13e550d78 68346034 debug extra icedove-dbg_3.0.11-1+squeeze13_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCAAGBQJQYQJlAAoJECbjyHWnRCDv+vUP/iiVT1pfQcVmuSU5D+CZHMkj M0xVmV6NqCbG8y5RD1hjSB9bgXlDeDCMI9EMiL/7n0sTljJuT93ur6p2o9dWG6qt J2qwXnycMED+dM2jhvb6nUOMOVR7blQkRSYriHuxtmAQ39wASRE6gpsZErKmftTL JLNJq6WdHh6q5jpEV9kItenJC7z3ejv0//NnnlB0wDWH6AQwLuw88eWaPuM+JRth 5zUqHCJoyfajNSLGva3QW/MyG5XfVE2bbsRSL+D2jWJF8FF1Kdq7FMEeb153Xfjn k1X91o4brNHahgUTYRb0PsDvv1m90N1s11fxOxtA61ozZnsgUyNroUdLj4tFnpmY 0ITfyz/PZDYBXMmi/Z+PIgVknzH8XUesAq7WqjWH5xtNjVSG/EJwGJdtce0+aW2V +ThyxHwNVDbFr9RopUx6ZrJ0SDDm4qfQrxLadyD9pDDDjB4jgVMq+JB/eAMBFk/p kUOGrHu/Gpuy01l4CA8eXyV4PUjNozjcDKxZQG1s+fh6S0sS69krmqETsHC7S8Fq 32Wvj9bq5J52AYhw7sNLEQRef1RroCBWTFXDZKVw4xutZ9DnjQRoi9ROKgm0Nl6O kZi/YxdOVLoXjIKSLWzyMyjz5rJMMmAl2qc41hE33qpr4Ebrmd9XrfPwxMSlGYlT FpI3xi2zBVkUsxshfKpz =224n -----END PGP SIGNATURE-----