Accepted xulrunner 1.8.0.15~pre080614h-0etch1 (source all amd64)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Thu, 17 Jul 2008 09:16:13 +0000
Source: xulrunner
Binary: libmozjs0d-dbg libnspr4-0d-dbg libxul0d-dbg xulrunner libnspr4-dev libxul0d libnss3-tools xulrunner-gnome-support libnspr4-0d libsmjs-dev libnss3-0d libmozjs0d libmozjs-dev python-xpcom libnss3-0d-dbg libxul-common libmozillainterfaces-java spidermonkey-bin libnss3-dev libxul-dev libsmjs1
Architecture: source all amd64
Version: 1.8.0.15~pre080614h-0etch1
Distribution: stable-security
Urgency: low
Maintainer: Mike Hommey <glandium@debian.org>
Changed-By: Alexander Sack <asac@canonical.com>
Description:
libmozillainterfaces-java - XPCOM bindings for Java
libmozjs-dev - Development files for the Mozilla SpiderMonkey JavaScript library
libmozjs0d - The Mozilla SpiderMonkey JavaScript library
libmozjs0d-dbg - Development files for the Mozilla SpiderMonkey JavaScript library
libnspr4-0d - NetScape Portable Runtime Library
libnspr4-0d-dbg - Development files for the NetScape Portable Runtime library
libnspr4-dev - Development files for the NetScape Portable Runtime library
libnss3-0d - Network Security Service libraries
libnss3-0d-dbg - Development files for the Network Security Service libraries
libnss3-dev - Development files for the Network Security Service libraries
libnss3-tools - Network Security Service tools
libsmjs-dev - Migration package for the Mozilla SpiderMonkey JavaScript library
libsmjs1 - Migration package for the Mozilla SpiderMonkey JavaScript library
libxul-common - Gecko engine library - common files
libxul-dev - Development files for the Gecko engine library
libxul0d - Gecko engine library
libxul0d-dbg - Development files for the Gecko engine library
python-xpcom - XPCOM bindings for Python
spidermonkey-bin - The SpiderMonkey Interpreter
xulrunner - XUL + XPCOM application runner
xulrunner-gnome-support - Support for Gnome in xulrunner applications
Changes:
xulrunner (1.8.0.15~pre080614h-0etch1) stable-security; urgency=low
.
[ Alexander Sack <asac@canonical.com> ]
* New security/stability upstream release (backports for 2.0.0.17 + 2.0.0.18)
* Upstream advisories (v2.0.0.17):
MFSA 2008-37 aka CVE-2008-0016 - UTF-8 URL stack buffer overflow
MFSA 2008-38 aka CVE-2008-3835 - nsXMLDocument::OnChannelRedirect() same-origin violation
MFSA 2008-40 aka CVE-2008-3837 - Forced mouse drag
MFSA 2008-41 aka CVE-2008-4058 - XPCnativeWrapper pollution
MFSA 2008-41 aka CVE-2008-4059 - XPCnativeWrapper pollution (Firefox 2)
MFSA 2008-41 aka CVE-2008-4060 - Documents without script handling objects
MFSA 2008-42 aka CVE-2008-4061 - Crashes with evidence of corruption; layout (rv:1.8.1.17)
MFSA 2008-42 aka CVE-2008-4062 - Crashes with evidence of corruption; javascript (rv:1.8.1.17)
MFSA 2008-43 aka CVE-2008-4065 - Stripped BOM characters
MFSA 2008-43 aka CVE-2008-4066 - HTML escaped low surrogates bug
MFSA 2008-44 aka CVE-2008-4067 - resource: traversal vulnerabilities (a)
MFSA 2008-44 aka CVE-2008-4068 - resource: traversal vulnerabilities (b)
MFSA 2008-45 aka CVE-2008-4069 - XBM image uninitialized memory reading
* Upstream advisories (v2.0.0.18):
MFSA 2008-47 aka CVE-2008-4582 - Information stealing via local shortcut files
MFSA 2008-48 aka CVE-2008-5012 - Image stealing via canvas and HTTP redirect
MFSA 2008-49 aka CVE-2008-5013 - Arbitrary code execution via Flash Player dynamic module unloading
MFSA 2008-50 aka CVE-2008-5014 - Crash and remote code execution via __proto__ tampering
MFSA 2008-52 aka CVE-2008-5017 - browser engine crashes with memory corruption (rv:1.8.1.18)
MFSA 2008-52 aka CVE-2008-5018 - javascript engine crashes with memory corruption (rv:1.8.1.18)
MFSA 2008-54 aka CVE-2008-0017 - Buffer overflow in http-index-format parser
MFSA 2008-55 aka CVE-2008-5021 - Crash and remote code execution in nsFrameManager
MFSA 2008-56 aka CVE-2008-5022 - nsXMLHttpRequest::NotifyEventListeners() same-origin violation
MFSA 2008-57 aka CVE-2008-5023 - -moz-binding property bypasses security checks on codebase principals
MFSA 2008-58 aka CVE-2008-5024 - Parsing error in E4X default namespace
Files:
2f56bfad80749a3af01a185cfc3a19e5 1984 devel optional xulrunner_1.8.0.15~pre080614h-0etch1.dsc
269ce29df92d5053f6d0fc659717c18b 43763318 devel optional xulrunner_1.8.0.15~pre080614h.orig.tar.gz
7f517d4bd904df70b6ead61c85e5eb71 144529 devel optional xulrunner_1.8.0.15~pre080614h-0etch1.diff.gz
516386bf8588e6210ac121d38cc67308 207752 libdevel optional libnspr4-dev_1.8.0.15~pre080614h-0etch1_all.deb
6bffe2de1c86a23ea69141da310df072 176254 libdevel optional libmozjs-dev_1.8.0.15~pre080614h-0etch1_all.deb
a83bac43079f44db9c6a8ba23638481a 37070 libs optional libsmjs1_1.8.0.15~pre080614h-0etch1_all.deb
ac110712c554bc90e6156ddf375c20e6 37108 libdevel optional libsmjs-dev_1.8.0.15~pre080614h-0etch1_all.deb
e9a4021391f5153eaca415b5f6e93fe6 1051896 libs optional libxul-common_1.8.0.15~pre080614h-0etch1_all.deb
39ab7259a30e82173bd736ff4d26b366 2637220 libdevel optional libxul-dev_1.8.0.15~pre080614h-0etch1_all.deb
75b9b3c909279253b358fe73c87ae920 231230 libdevel optional libnss3-dev_1.8.0.15~pre080614h-0etch1_all.deb
388688d0bfcb0a5c4abde96f9fb24c98 1032080 libdevel extra libmozillainterfaces-java_1.8.0.15~pre080614h-0etch1_all.deb
9124a96cd6b202d076a35829b542f6f6 278728 devel optional xulrunner_1.8.0.15~pre080614h-0etch1_amd64.deb
2e6a6559a22ce55f2b6b9331b0bfbd68 69360 devel optional xulrunner-gnome-support_1.8.0.15~pre080614h-0etch1_amd64.deb
d179d55f788e6fbaf2259446d79c342c 148946 libs optional libnspr4-0d_1.8.0.15~pre080614h-0etch1_amd64.deb
36ced9e2336ccaa648a15c76707f8645 304624 libdevel extra libnspr4-0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
7e6147ae3531fb175cdf637a25f4dc33 356028 libs optional libmozjs0d_1.8.0.15~pre080614h-0etch1_amd64.deb
ade61fc66030701ba9d62086288403bf 755560 libdevel extra libmozjs0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
803733e356f2f74037a6f3a7d9a4a91f 53340 interpreters optional spidermonkey-bin_1.8.0.15~pre080614h-0etch1_amd64.deb
7683694615827e8674c59034978b86b1 6343406 libs optional libxul0d_1.8.0.15~pre080614h-0etch1_amd64.deb
e18a8c41099328f6979c27614a81b83c 45217322 libdevel extra libxul0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
09a7217cbe1b1180c71ae7b16a306747 810296 libs optional libnss3-0d_1.8.0.15~pre080614h-0etch1_amd64.deb
7984141447417ad48f657e5752a197c5 671010 admin optional libnss3-tools_1.8.0.15~pre080614h-0etch1_amd64.deb
69775ab87c4c2677faf2fbe8ed1c4617 3177838 libdevel extra libnss3-0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
7795ccbd3edeb72623450ec3b0c407f9 126632 python extra python-xpcom_1.8.0.15~pre080614h-0etch1_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iQIVAwUBSSEA5qBE/gcUDGZkAQIfRhAAvlswXaoBldpYyT0bmkyx5Z00pR+JH3QE
cKoAbY74uKHYGFZ19kFDq7KpOFvN7qtdawju5J7c7F4EVtIY8u3SbnZJAzi5pdec
3QiOEuc3xW2OQDY/J373o7gIwHRkGGkprhF2l9Twp1TS2uitVDeq5an6fCPDzMoY
P9U/rJeQHEkDEdHdC6ancFXZSUMRYcTzV2xlXU9sXIPl0DuyxMrX1vx90sZwB20+
NR+49yMW/i/wVeM/L5iUF84dmZNGpX8MmIFoclj75lC7vbJ+3yfbig8BxWmczsud
x4oftKV/P7OdeFcJ6yDUzMCgJuAE0iW+DUClKt+xgSP/lShMJaJTisRZ98Y03d6c
oQNZD1u059rWdIUkZkZ/eLnbpRsQ2HZwMxIhSZv4gFiQpM4YXO2zhmAgOfFnLnWm
6RjPircW/Oalj5EdzVmS1MRVCYDpfcAANgP+GLKVhixu8ULrEukYztOw4Nl+I079
6aupQf9Bo8+c47HMHv1jCVuqocTPuOL5rCgWEi+Usud8DtTeIALEDJz7CC4LC3Ma
0CcRvONT0n+B7dpBXi4JN0u4oCzULQZWyLxAIJAt4i/tH1Gd+1FHKritMgZ9PIeM
9BIO9y5/CbApLD53hG4jwipfFPbRMFZLYerWVXAk61a2VTmublKa+ziUeh/z76FS
8+XN0pkzDjA=
=sjsx
-----END PGP SIGNATURE-----
Accepted:
libmozillainterfaces-java_1.8.0.15~pre080614h-0etch1_all.deb
to pool/main/x/xulrunner/libmozillainterfaces-java_1.8.0.15~pre080614h-0etch1_all.deb
libmozjs-dev_1.8.0.15~pre080614h-0etch1_all.deb
to pool/main/x/xulrunner/libmozjs-dev_1.8.0.15~pre080614h-0etch1_all.deb
libmozjs0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
to pool/main/x/xulrunner/libmozjs0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
libmozjs0d_1.8.0.15~pre080614h-0etch1_amd64.deb
to pool/main/x/xulrunner/libmozjs0d_1.8.0.15~pre080614h-0etch1_amd64.deb
libnspr4-0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
to pool/main/x/xulrunner/libnspr4-0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
libnspr4-0d_1.8.0.15~pre080614h-0etch1_amd64.deb
to pool/main/x/xulrunner/libnspr4-0d_1.8.0.15~pre080614h-0etch1_amd64.deb
libnspr4-dev_1.8.0.15~pre080614h-0etch1_all.deb
to pool/main/x/xulrunner/libnspr4-dev_1.8.0.15~pre080614h-0etch1_all.deb
libnss3-0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
to pool/main/x/xulrunner/libnss3-0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
libnss3-0d_1.8.0.15~pre080614h-0etch1_amd64.deb
to pool/main/x/xulrunner/libnss3-0d_1.8.0.15~pre080614h-0etch1_amd64.deb
libnss3-dev_1.8.0.15~pre080614h-0etch1_all.deb
to pool/main/x/xulrunner/libnss3-dev_1.8.0.15~pre080614h-0etch1_all.deb
libnss3-tools_1.8.0.15~pre080614h-0etch1_amd64.deb
to pool/main/x/xulrunner/libnss3-tools_1.8.0.15~pre080614h-0etch1_amd64.deb
libsmjs-dev_1.8.0.15~pre080614h-0etch1_all.deb
to pool/main/x/xulrunner/libsmjs-dev_1.8.0.15~pre080614h-0etch1_all.deb
libsmjs1_1.8.0.15~pre080614h-0etch1_all.deb
to pool/main/x/xulrunner/libsmjs1_1.8.0.15~pre080614h-0etch1_all.deb
libxul-common_1.8.0.15~pre080614h-0etch1_all.deb
to pool/main/x/xulrunner/libxul-common_1.8.0.15~pre080614h-0etch1_all.deb
libxul-dev_1.8.0.15~pre080614h-0etch1_all.deb
to pool/main/x/xulrunner/libxul-dev_1.8.0.15~pre080614h-0etch1_all.deb
libxul0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
to pool/main/x/xulrunner/libxul0d-dbg_1.8.0.15~pre080614h-0etch1_amd64.deb
libxul0d_1.8.0.15~pre080614h-0etch1_amd64.deb
to pool/main/x/xulrunner/libxul0d_1.8.0.15~pre080614h-0etch1_amd64.deb
python-xpcom_1.8.0.15~pre080614h-0etch1_amd64.deb
to pool/main/x/xulrunner/python-xpcom_1.8.0.15~pre080614h-0etch1_amd64.deb
spidermonkey-bin_1.8.0.15~pre080614h-0etch1_amd64.deb
to pool/main/x/xulrunner/spidermonkey-bin_1.8.0.15~pre080614h-0etch1_amd64.deb
xulrunner-gnome-support_1.8.0.15~pre080614h-0etch1_amd64.deb
to pool/main/x/xulrunner/xulrunner-gnome-support_1.8.0.15~pre080614h-0etch1_amd64.deb
xulrunner_1.8.0.15~pre080614h-0etch1.diff.gz
to pool/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1.diff.gz
xulrunner_1.8.0.15~pre080614h-0etch1.dsc
to pool/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1.dsc
xulrunner_1.8.0.15~pre080614h-0etch1_amd64.deb
to pool/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h-0etch1_amd64.deb
xulrunner_1.8.0.15~pre080614h.orig.tar.gz
to pool/main/x/xulrunner/xulrunner_1.8.0.15~pre080614h.orig.tar.gz
Reply to: