Subject: CVS commit: pkgsrc/mail/thunderbird
From: Ryo ONODERA
Date: 2018-01-24 17:39:02
Message id: 20180124163902.C8351FBDE@cvs.NetBSD.org

Log Message:
Update to 52.5.2

Changelog:
Fix
 This releases fixes the "Mailsploit" vulnerability and other \ 
vulnerabilities
 detected by the "Cure53" audit. For details and various other security
 fixes see here.

CVE-2017-7845: Buffer overflow when drawing and validating elements with
  ANGLE library using Direct 3D 9
CVE-2017-7846: JavaScript Execution via RSS in mailbox:// origin
CVE-2017-7847: Local path string can be leaked from RSS feed
CVE-2017-7848: RSS Feed vulnerable to new line Injection
CVE-2017-7829: Mailsploit part 1: From address with encoded null character
  is cut off in message header display

Files:
RevisionActionfile
1.201modifypkgsrc/mail/thunderbird/Makefile
1.195modifypkgsrc/mail/thunderbird/distinfo