Subject: CVS commit: [pkgsrc-2009Q3] pkgsrc
From: S.P.Zeidler
Date: 2009-12-20 20:41:08
Message id: 20091220194108.E247B175DD@cvs.netbsd.org

Log Message:
Pullup ticket 2953 - requested by tnn
security update

Revisions pulled up:
- pkgsrc/devel/xulrunner/Makefile               by patch
- pkgsrc/devel/xulrunner/distinfo               by patch
- pkgsrc/devel/xulrunner/mozilla-common.mk      by patch
- pkgsrc/www/firefox/Makefile                   by patch

   -------------------------------------------------------------------------
   firefox-3.5.6 & xulrunner-1.9.1.6 fix the following vulnerabilities:

   MFSA 2009-71 GeckoActiveXObject exception messages can be used to
                enumerate installed COM objects
   MFSA 2009-70 Privilege escalation via chrome window.opener
   MFSA 2009-69 Location bar spoofing vulnerabilities
   MFSA 2009-68 NTLM reflection vulnerability
   MFSA 2009-67 Integer overflow, crash in libtheora video library
   MFSA 2009-66 Memory safety fixes in liboggplay media library
   MFSA 2009-65 Crashes with evidence of memory corruption

Files:
RevisionActionfile
1.23.2.2modifypkgsrc/devel/xulrunner/Makefile
1.12.2.2modifypkgsrc/devel/xulrunner/distinfo
1.1.2.2modifypkgsrc/devel/xulrunner/mozilla-common.mk
1.59.2.2modifypkgsrc/www/firefox/Makefile