Received: from mail.netbsd.org (mail.netbsd.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mail.netbsd.org", Issuer "Postmaster NetBSD.org" (verified OK)) by mollari.NetBSD.org (Postfix) with ESMTPS id 7A9AB7A217 for ; Sun, 26 Mar 2017 04:05:42 +0000 (UTC) Received: by mail.netbsd.org (Postfix, from userid 605) id 2AEB8855EE; Sun, 26 Mar 2017 04:05:42 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id AC702855C3 for ; Sun, 26 Mar 2017 04:05:41 +0000 (UTC) X-Virus-Scanned: amavisd-new at netbsd.org Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id 7EExI_Mjq7f1 for ; Sun, 26 Mar 2017 04:05:41 +0000 (UTC) Received: from cvs.NetBSD.org (ivanova.netbsd.org [199.233.217.197]) by mail.netbsd.org (Postfix) with ESMTP id 0DB7284CE1 for ; Sun, 26 Mar 2017 04:05:41 +0000 (UTC) Received: by cvs.NetBSD.org (Postfix, from userid 500) id 03B6AFBE4; Sun, 26 Mar 2017 04:05:41 +0000 (UTC) Content-Transfer-Encoding: 7bit Content-Type: multipart/mixed; boundary="_----------=_1490501140183120" MIME-Version: 1.0 Date: Sun, 26 Mar 2017 04:05:40 +0000 From: "Ryo ONODERA" Subject: CVS commit: pkgsrc/mail/thunderbird To: pkgsrc-changes@NetBSD.org Reply-To: ryoon@netbsd.org X-Mailer: log_accum Message-Id: <20170326040541.03B6AFBE4@cvs.NetBSD.org> Sender: pkgsrc-changes-owner@NetBSD.org List-Id: pkgsrc-changes.NetBSD.org Precedence: bulk This is a multi-part message in MIME format. --_----------=_1490501140183120 Content-Disposition: inline Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset="US-ASCII" Module Name: pkgsrc Committed By: ryoon Date: Sun Mar 26 04:05:40 UTC 2017 Modified Files: pkgsrc/mail/thunderbird: Makefile distinfo pkgsrc/mail/thunderbird/patches: patch-mozilla_ipc_chromium_src_base_message__pump__libevent.cc Log Message: Update to 45.8.0 Changelog: #CVE-2017-5400: asm.js JIT-spray bypass of ASLR and DEP #CVE-2017-5401: Memory Corruption when handling ErrorResult #CVE-2017-5402: Use-after-free working with events in FontFace objects #CVE-2017-5404: Use-after-free working with ranges in selections #CVE-2017-5407: Pixel and history stealing via floating-point timing side channel with SVG filters #CVE-2017-5410: Memory corruption during JavaScript garbage collection incremental sweeping #CVE-2017-5408: Cross-origin reading of video captions in violation of CORS #CVE-2017-5405: FTP response codes can cause use of uninitialized values for ports #CVE-2017-5398: Memory safety bugs fixed in Thunderbird 45.8 To generate a diff of this commit: cvs rdiff -u -r1.188 -r1.189 pkgsrc/mail/thunderbird/Makefile cvs rdiff -u -r1.187 -r1.188 pkgsrc/mail/thunderbird/distinfo cvs rdiff -u -r1.3 -r1.4 \ pkgsrc/mail/thunderbird/patches/patch-mozilla_ipc_chromium_src_base_message__pump__libevent.cc Please note that diffs are not public domain; they are subject to the copyright notices on the relevant files. --_----------=_1490501140183120 Content-Disposition: inline Content-Length: 4694 Content-Transfer-Encoding: binary Content-Type: text/x-diff; charset=us-ascii Modified files: Index: pkgsrc/mail/thunderbird/Makefile diff -u pkgsrc/mail/thunderbird/Makefile:1.188 pkgsrc/mail/thunderbird/Makefile:1.189 --- pkgsrc/mail/thunderbird/Makefile:1.188 Wed Mar 1 13:30:19 2017 +++ pkgsrc/mail/thunderbird/Makefile Sun Mar 26 04:05:40 2017 @@ -1,8 +1,8 @@ -# $NetBSD: Makefile,v 1.188 2017/03/01 13:30:19 ryoon Exp $ +# $NetBSD: Makefile,v 1.189 2017/03/26 04:05:40 ryoon Exp $ DISTNAME= thunderbird-${TB_VER}.source PKGNAME= thunderbird-${TB_VER} -TB_VER= 45.7.1 +TB_VER= 45.8.0 CATEGORIES= mail MASTER_SITES= ${MASTER_SITE_MOZILLA:=thunderbird/releases/${TB_VER}/source/} EXTRACT_SUFX= .tar.xz Index: pkgsrc/mail/thunderbird/distinfo diff -u pkgsrc/mail/thunderbird/distinfo:1.187 pkgsrc/mail/thunderbird/distinfo:1.188 --- pkgsrc/mail/thunderbird/distinfo:1.187 Wed Mar 1 13:30:19 2017 +++ pkgsrc/mail/thunderbird/distinfo Sun Mar 26 04:05:40 2017 @@ -1,9 +1,9 @@ -$NetBSD: distinfo,v 1.187 2017/03/01 13:30:19 ryoon Exp $ +$NetBSD: distinfo,v 1.188 2017/03/26 04:05:40 ryoon Exp $ -SHA1 (thunderbird-45.7.1.source.tar.xz) = ad050dbb54f226aafc3b44891b64a74286549d40 -RMD160 (thunderbird-45.7.1.source.tar.xz) = 7d84922d5c6559f33640eee76a007d554b709b35 -SHA512 (thunderbird-45.7.1.source.tar.xz) = aa1231169cfe243a257e6b9088281b85d0cf75207e3b9ebeda7792567a86f6098fb5c74dc397e3eeeb1925d221d2fb1b17df8762afd115eff9ad4d1370a49e56 -Size (thunderbird-45.7.1.source.tar.xz) = 201127704 bytes +SHA1 (thunderbird-45.8.0.source.tar.xz) = 36fc106885d612966ec3be047f4e7d3fa06dc04a +RMD160 (thunderbird-45.8.0.source.tar.xz) = 8d4ab2feabee0402fbfe38168c51187b1f26221d +SHA512 (thunderbird-45.8.0.source.tar.xz) = f8ba08d874fb1a09ac9ba5d4d1f46cefe801783ba4bf82eee682ac2ecc4e231d07033a80e036ad04bda7780c093fb7bc3122a23dc6e19c12f18fb7168dc78deb +Size (thunderbird-45.8.0.source.tar.xz) = 201199348 bytes SHA1 (patch-calendar_lightning_Makefile.in) = 02a1528f2da82f1d4ff4931a7d7dc8227b7fa9f2 SHA1 (patch-calendar_lightning_build_universal.mk) = 86dc2c6b4f9feb835570111078aa5d08a389d0da SHA1 (patch-calendar_providers_gdata_Makefile.in) = 0e90ddc9aecc817b0b150bbc37d23ddec97b093e @@ -52,7 +52,7 @@ SHA1 (patch-mozilla_intl_hyphenation_glu SHA1 (patch-mozilla_ipc_chromium_src_base_atomicops.h) = b70f38db87e80de06f061e7ee7664d47b1000f12 SHA1 (patch-mozilla_ipc_chromium_src_base_file__util__posix.cc) = aff83e28eb7af0f04c68b8336441eaef04bb763c SHA1 (patch-mozilla_ipc_chromium_src_base_message__loop.cc) = b4d4e7fd53632751cf4624044815da3a9f20819c -SHA1 (patch-mozilla_ipc_chromium_src_base_message__pump__libevent.cc) = e7ec8e3f7aae56a47a328f0f3a6708eb85ee07c9 +SHA1 (patch-mozilla_ipc_chromium_src_base_message__pump__libevent.cc) = 71825dd5ab9e8f3055fc276558dc73f5489ade15 SHA1 (patch-mozilla_ipc_chromium_src_base_platform__thread.h) = a0d0cff52de77a45def4789a7f6f30603c13f07a SHA1 (patch-mozilla_ipc_chromium_src_base_platform__thread__posix.cc) = 9998c382302a022ba1027f4346c53dcd4ef0b52f SHA1 (patch-mozilla_ipc_chromium_src_base_process__util.h) = 56b13a62b9bb6b4a0b94ed285f33fa5d67c56dc8 Index: pkgsrc/mail/thunderbird/patches/patch-mozilla_ipc_chromium_src_base_message__pump__libevent.cc diff -u pkgsrc/mail/thunderbird/patches/patch-mozilla_ipc_chromium_src_base_message__pump__libevent.cc:1.3 pkgsrc/mail/thunderbird/patches/patch-mozilla_ipc_chromium_src_base_message__pump__libevent.cc:1.4 --- pkgsrc/mail/thunderbird/patches/patch-mozilla_ipc_chromium_src_base_message__pump__libevent.cc:1.3 Sun Apr 17 18:33:50 2016 +++ pkgsrc/mail/thunderbird/patches/patch-mozilla_ipc_chromium_src_base_message__pump__libevent.cc Sun Mar 26 04:05:40 2017 @@ -1,16 +1,16 @@ -$NetBSD: patch-mozilla_ipc_chromium_src_base_message__pump__libevent.cc,v 1.3 2016/04/17 18:33:50 ryoon Exp $ +$NetBSD: patch-mozilla_ipc_chromium_src_base_message__pump__libevent.cc,v 1.4 2017/03/26 04:05:40 ryoon Exp $ ---- mozilla/ipc/chromium/src/base/message_pump_libevent.cc.orig 2016-04-07 21:33:19.000000000 +0000 +--- mozilla/ipc/chromium/src/base/message_pump_libevent.cc.orig 2017-03-05 20:58:25.000000000 +0000 +++ mozilla/ipc/chromium/src/base/message_pump_libevent.cc @@ -20,6 +20,7 @@ // This macro checks that the _EVENT_SIZEOF_* constants defined in // ipc/chromiume/src/third_party//event2/event-config.h are correct. +#if 0 + #if defined(_EVENT_SIZEOF_SHORT) #define CHECK_EVENT_SIZEOF(TYPE, type) \ static_assert(_EVENT_SIZEOF_##TYPE == sizeof(type), \ - "bad _EVENT_SIZEOF_"#TYPE); -@@ -30,6 +31,7 @@ CHECK_EVENT_SIZEOF(PTHREAD_T, pthread_t) +@@ -38,6 +39,7 @@ CHECK_EVENT_SIZEOF(PTHREAD_T, pthread_t) CHECK_EVENT_SIZEOF(SHORT, short); CHECK_EVENT_SIZEOF(SIZE_T, size_t); CHECK_EVENT_SIZEOF(VOID_P, void*); --_----------=_1490501140183120--