Tue Jul 9 10:57:20 2013 UTC ()
Update to 17.0.7

Changelog:
    FIXED
    Security fixes can be found here

Fixed in Thunderbird 17.0.7
MFSA 2013-59 XrayWrappers can be bypassed to run user defined methods in a privileged context
MFSA 2013-56 PreserveWrapper has inconsistent behavior
MFSA 2013-55 SVG filters can lead to information disclosure
MFSA 2013-54 Data in the body of XHR HEAD requests leads to CSRF attacks
MFSA 2013-53 Execution of unmapped memory through onreadystatechange event
MFSA 2013-51 Privileged content access and execution via XBL
MFSA 2013-50 Memory corruption found using Address Sanitizer
MFSA 2013-49 Miscellaneous memory safety hazards (rv:22.0 / rv:17.0.7)


(ryoon)
diff -r1.117 -r1.118 pkgsrc/mail/thunderbird/Makefile
diff -r1.122 -r1.123 pkgsrc/mail/thunderbird/distinfo

cvs diff -r1.117 -r1.118 pkgsrc/mail/thunderbird/Makefile (expand / switch to unified diff)

--- pkgsrc/mail/thunderbird/Makefile 2013/06/06 12:54:42 1.117
+++ pkgsrc/mail/thunderbird/Makefile 2013/07/09 10:57:20 1.118
@@ -1,21 +1,20 @@ @@ -1,21 +1,20 @@
1# $NetBSD: Makefile,v 1.117 2013/06/06 12:54:42 wiz Exp $ 1# $NetBSD: Makefile,v 1.118 2013/07/09 10:57:20 ryoon Exp $
2# 2#
3 3
4DISTNAME= # empty 4DISTNAME= # empty
5PKGNAME= thunderbird-${TB_VER} 5PKGNAME= thunderbird-${TB_VER}
6TB_VER= 17.0.6 6TB_VER= 17.0.7
7LIGHTNINGVER= 1.9 7LIGHTNINGVER= 1.9
8PKGREVISION= 3 
9CATEGORIES= mail 8CATEGORIES= mail
10MASTER_SITES= ${MASTER_SITE_MOZILLA_ESR:=thunderbird/releases/${TB_VER}esr/source/} \ 9MASTER_SITES= ${MASTER_SITE_MOZILLA_ESR:=thunderbird/releases/${TB_VER}esr/source/} \
11 ${MASTER_SITE_MOZILLA_ALL:=thunderbird/releases/${TB_VER}esr/source/} 10 ${MASTER_SITE_MOZILLA_ALL:=thunderbird/releases/${TB_VER}esr/source/}
12DISTFILES= thunderbird-${TB_VER}esr.source.tar.bz2 \ 11DISTFILES= thunderbird-${TB_VER}esr.source.tar.bz2 \
13 lightning-${LIGHTNINGVER}.source.tar.bz2 12 lightning-${LIGHTNINGVER}.source.tar.bz2
14SITES.lightning-${LIGHTNINGVER}.source.tar.bz2= ${MASTER_SITE_MOZILLA:=calendar/lightning/releases/${LIGHTNINGVER}/source/} 13SITES.lightning-${LIGHTNINGVER}.source.tar.bz2= ${MASTER_SITE_MOZILLA:=calendar/lightning/releases/${LIGHTNINGVER}/source/}
15EXTRACT_DIR.lightning-${LIGHTNINGVER}.source.tar.bz2= ${WRKSRC}/lightning 14EXTRACT_DIR.lightning-${LIGHTNINGVER}.source.tar.bz2= ${WRKSRC}/lightning
16 15
17MAINTAINER= pkgsrc-users@NetBSD.org 16MAINTAINER= pkgsrc-users@NetBSD.org
18HOMEPAGE= http://www.mozillamessaging.com/en-US/thunderbird/ 17HOMEPAGE= http://www.mozillamessaging.com/en-US/thunderbird/
19COMMENT= Organize, secure and customize your mail 18COMMENT= Organize, secure and customize your mail
20 19
21USE_TOOLS+= unzip pax 20USE_TOOLS+= unzip pax

cvs diff -r1.122 -r1.123 pkgsrc/mail/thunderbird/distinfo (expand / switch to unified diff)

--- pkgsrc/mail/thunderbird/distinfo 2013/05/24 09:59:54 1.122
+++ pkgsrc/mail/thunderbird/distinfo 2013/07/09 10:57:20 1.123
@@ -1,24 +1,21 @@ @@ -1,24 +1,21 @@
1$NetBSD: distinfo,v 1.122 2013/05/24 09:59:54 wiz Exp $ 1$NetBSD: distinfo,v 1.123 2013/07/09 10:57:20 ryoon Exp $
2 2
3SHA1 (enigmail-1.4.5.tar.gz) = 16d0450a9f5fb4de0e9cc5b9f8091dce4b070aaf 
4RMD160 (enigmail-1.4.5.tar.gz) = 860a1ca813fd2ccae69ac0afe07affd39611e56a 
5Size (enigmail-1.4.5.tar.gz) = 1269207 bytes 
6SHA1 (lightning-1.9.source.tar.bz2) = 3cc625649debed6f7403c862f166b771b80b92ce 3SHA1 (lightning-1.9.source.tar.bz2) = 3cc625649debed6f7403c862f166b771b80b92ce
7RMD160 (lightning-1.9.source.tar.bz2) = 3396533847c05ed37537b9a78d771e55f767bea6 4RMD160 (lightning-1.9.source.tar.bz2) = 3396533847c05ed37537b9a78d771e55f767bea6
8Size (lightning-1.9.source.tar.bz2) = 113944316 bytes 5Size (lightning-1.9.source.tar.bz2) = 113944316 bytes
9SHA1 (thunderbird-17.0.6esr.source.tar.bz2) = bb70b820b5b518e1bff4c4ec0ff3416b5a1a4f21 6SHA1 (thunderbird-17.0.7esr.source.tar.bz2) = 4fbfa738e43d67022a6b426ebb26efb86ec2c52a
10RMD160 (thunderbird-17.0.6esr.source.tar.bz2) = f98b5f48a774051a1390fa50d4178403ab032293 7RMD160 (thunderbird-17.0.7esr.source.tar.bz2) = 1159a105c84b06a8125410a7f88b8a8dc8a45dbb
11Size (thunderbird-17.0.6esr.source.tar.bz2) = 113885201 bytes 8Size (thunderbird-17.0.7esr.source.tar.bz2) = 113569841 bytes
12SHA1 (patch-aa) = c73e3fa16dea308a0cf6ca684529958336c788f3 9SHA1 (patch-aa) = c73e3fa16dea308a0cf6ca684529958336c788f3
13SHA1 (patch-aa-toplevel) = 1207a234377bab854f59b13ce51efe810913f1e0 10SHA1 (patch-aa-toplevel) = 1207a234377bab854f59b13ce51efe810913f1e0
14SHA1 (patch-ab) = 7432f73e9771260849d99e14008164bd3d564bf8 11SHA1 (patch-ab) = 7432f73e9771260849d99e14008164bd3d564bf8
15SHA1 (patch-ac) = 3d54eef3657bf39b73e2851a33b8ee1aa9408131 12SHA1 (patch-ac) = 3d54eef3657bf39b73e2851a33b8ee1aa9408131
16SHA1 (patch-ad) = 5f225b1db28a7217d9225ffc03fe3a40b453d7f7 13SHA1 (patch-ad) = 5f225b1db28a7217d9225ffc03fe3a40b453d7f7
17SHA1 (patch-ae) = 23648401a4f5335a370ff60ae1e1fb37a28404e7 14SHA1 (patch-ae) = 23648401a4f5335a370ff60ae1e1fb37a28404e7
18SHA1 (patch-af) = 371779510213ba63eff81f1258d3d8686b78a7e7 15SHA1 (patch-af) = 371779510213ba63eff81f1258d3d8686b78a7e7
19SHA1 (patch-ag) = bf447af7731e1b508df5b03ec0055e463c1c6db9 16SHA1 (patch-ag) = bf447af7731e1b508df5b03ec0055e463c1c6db9
20SHA1 (patch-aj) = 2b94927755ffebbe54516b5d66d109cc2e54c400 17SHA1 (patch-aj) = 2b94927755ffebbe54516b5d66d109cc2e54c400
21SHA1 (patch-ak) = b47277baa1137a7610445b7c4dd147b331d5c5e6 18SHA1 (patch-ak) = b47277baa1137a7610445b7c4dd147b331d5c5e6
22SHA1 (patch-al) = 9970e89e92ff8b120119b560cb661eabd3a387de 19SHA1 (patch-al) = 9970e89e92ff8b120119b560cb661eabd3a387de
23SHA1 (patch-am) = 2d38162da23828ebee56e56a00ea086992d554ce 20SHA1 (patch-am) = 2d38162da23828ebee56e56a00ea086992d554ce
24SHA1 (patch-an) = 96139c682b84432e4e8a0be98db56abee89daf02 21SHA1 (patch-an) = 96139c682b84432e4e8a0be98db56abee89daf02