Please update xulrunner to 1.8.1.16 version.

Bug #254618 reported by Devid Antonio Filoni
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
xulrunner (Ubuntu)
Fix Released
High
Unassigned
Hardy
Won't Fix
Undecided
Unassigned

Bug Description

Binary package hint: xulrunner

Please update xulrunner to 1.8.1.16 version.

From Firefox Security Advisory:
 + Fixed in Firefox 2.0.0.16
     - MFSA 2008-35 Command-line URLs launch multiple tabs when Firefox not running
     - MFSA 2008-34 Remote code execution by overflowing CSS reference counter
 + Fixed in Firefox 2.0.0.15
     - MFSA 2008-33 Crash and remote code execution in block reflow
     - MFSA 2008-32 Remote site run as local file via Windows URL shortcut
     - MFSA 2008-31 Peer-trusted certs can use alt names to spoof
     - MFSA 2008-30 File location URL in directory listings not escaped properly
     - MFSA 2008-29 Faulty .properties file results in uninitialized memory being used
     - MFSA 2008-28 Arbitrary socket connections with Java LiveConnect on Mac OS X
     - MFSA 2008-27 Arbitrary file upload via originalTarget and DOM Range
     - MFSA 2008-25 Arbitrary code execution in mozIJSSubScriptLoader.loadSubScript()
     - MFSA 2008-24 Chrome script loading from fastload file
     - MFSA 2008-23 Signed JAR tampering
     - MFSA 2008-22 XSS through JavaScript same-origin violation
     - MFSA 2008-21 Crashes with evidence of memory corruption (rv:1.8.1.15)

From Thunderbird Security Advisory:
 + Fixed in Thunderbird 2.0.0.16
     - MFSA 2008-34 Remote code execution by overflowing CSS reference counter
     - MFSA 2008-33 Crash and remote code execution in block reflow
     - MFSA 2008-31 Peer-trusted certs can use alt names to spoof
     - MFSA 2008-29 Faulty .properties file results in uninitialized memory being used
     - MFSA 2008-26 Buffer length checks in MIME processing
     - MFSA 2008-25 Arbitrary code execution in mozIJSSubScriptLoader.loadSubScript()
     - MFSA 2008-24 Chrome script loading from fastload file
     - MFSA 2008-21 Crashes with evidence of memory corruption (rv:1.8.1.15)

Revision history for this message
Devid Antonio Filoni (d.filoni) wrote :

I'm working on this.

Changed in xulrunner:
assignee: nobody → d.filoni
status: New → In Progress
Revision history for this message
Devid Antonio Filoni (d.filoni) wrote :
Changed in xulrunner:
assignee: d.filoni → nobody
status: In Progress → Confirmed
Revision history for this message
Devid Antonio Filoni (d.filoni) wrote :

New diff.gz

Revision history for this message
Devid Antonio Filoni (d.filoni) wrote :

Debdiff between old and new debian dirs

Revision history for this message
Alexander Sack (asac) wrote :

good. uploading to intrepid.

Changed in xulrunner:
importance: Undecided → High
status: Confirmed → Fix Committed
Changed in xulrunner:
assignee: nobody → d.filoni
status: New → In Progress
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package xulrunner - 1.8.1.16+nobinonly-0ubuntu1

---------------
xulrunner (1.8.1.16+nobinonly-0ubuntu1) intrepid; urgency=low

  * New upstream release (taken from upstream CVS), LP: #254618.
  * Fix MFSA 2008-35, MFSA 2008-34, MFSA 2008-33, MFSA 2008-32, MFSA 2008-31,
    MFSA 2008-30, MFSA 2008-29, MFSA 2008-28, MFSA 2008-27, MFSA 2008-25,
    MFSA 2008-24, MFSA 2008-23, MFSA 2008-22, MFSA 2008-21, MFSA 2008-26 also
    known as CVE-2008-2933, CVE-2008-2785, CVE-2008-2811, CVE-2008-2810,
    CVE-2008-2809, CVE-2008-2808, CVE-2008-2807, CVE-2008-2806, CVE-2008-2805,
    CVE-2008-2803, CVE-2008-2802, CVE-2008-2801, CVE-2008-2800, CVE-2008-2798.
  * Drop 89_bz419350_attachment_306066 patch, merged upstream.
  * Bump Standards-Version to 3.8.0.

 -- Devid Antonio Filoni <email address hidden> Mon, 25 Aug 2008 13:04:18 +0200

Changed in xulrunner:
status: Fix Committed → Fix Released
Changed in xulrunner:
assignee: d.filoni → nobody
status: In Progress → New
Revision history for this message
Rolf Leggewie (r0lf) wrote :

Hardy has seen the end of its life and is no longer receiving any updates. Marking the Hardy task for this ticket as "Won't Fix".

Changed in xulrunner (Ubuntu Hardy):
status: New → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.