summaryrefslogtreecommitdiff
path: root/devel/xulrunner
AgeCommit message (Collapse)AuthorFilesLines
2010-09-11Pullup ticket 3219 - requested by tnnspz10-65/+61
security update Revisions pulled up: - pkgsrc/devel/nspr/Makefile 1.37 - pkgsrc/devel/nspr/PLIST 1.11 - pkgsrc/devel/nss/Makefile 1.38 - pkgsrc/devel/xulrunner/PLIST 1.24 - pkgsrc/devel/xulrunner/dist.mk 1.14 - pkgsrc/devel/xulrunner/distinfo 1.36 - pkgsrc/devel/xulrunner/mozilla-common.mk 1.16 - pkgsrc/devel/xulrunner/patches/patch-ag 1.2 - pkgsrc/devel/xulrunner/patches/patch-al 1.2 - pkgsrc/devel/xulrunner/patches/patch-ap 1.4 - pkgsrc/devel/xulrunner/patches/patch-mc 1.2 - pkgsrc/devel/xulrunner/patches/patch-mm 1.3 - pkgsrc/devel/xulrunner/patches/patch-mn 1.3 ------------------------------------------------------------------------- Modified Files: pkgsrc/devel/nspr: Makefile PLIST Log Message: Update to nspr-4.8.6 (via firefox-3.6.9). Changes unknown. To generate a diff of this commit: cvs rdiff -u -r1.36 -r1.37 pkgsrc/devel/nspr/Makefile cvs rdiff -u -r1.10 -r1.11 pkgsrc/devel/nspr/PLIST ------------------------------------------------------------------------- Modified Files: pkgsrc/devel/nss: Makefile Log Message: Update to nss-3.12.7.0 (via firefox-3.6.9). Changes unknown. To generate a diff of this commit: cvs rdiff -u -r1.37 -r1.38 pkgsrc/devel/nss/Makefile ------------------------------------------------------------------------- Modified Files: pkgsrc/devel/xulrunner: PLIST dist.mk distinfo mozilla-common.mk pkgsrc/devel/xulrunner/patches: patch-ag patch-al patch-ap patch-mc patch-mm patch-mn Log Message: Update to firefox-3.6.9 (xulrunner-1.9.2.9) MFSA 2010-63 Information leak via XMLHttpRequest statusText MFSA 2010-62 Copy-and-paste or drag-and-drop into designMode document allows XSS MFSA 2010-61 UTF-7 XSS by overriding document charset using <object> type attribute MFSA 2010-59 SJOW creates scope chains ending in outer object MFSA 2010-58 Crash on Mac using fuzzed font in data: URL MFSA 2010-57 Crash and remote code execution in normalizeDocument MFSA 2010-56 Dangling pointer vulnerability in nsTreeContentView MFSA 2010-55 XUL tree removal crash and remote code execution MFSA 2010-54 Dangling pointer vulnerability in nsTreeSelection MFSA 2010-53 Heap buffer overflow in nsTextFrameUtils::TransformText MFSA 2010-52 Windows XP DLL loading vulnerability MFSA 2010-51 Dangling pointer vulnerability using DOM plugin array MFSA 2010-50 Frameset integer overflow vulnerability MFSA 2010-49 Miscellaneous memory safety hazards (rv:1.9.2.9/ 1.9.1.12) To generate a diff of this commit: cvs rdiff -u -r1.23 -r1.24 pkgsrc/devel/xulrunner/PLIST cvs rdiff -u -r1.13 -r1.14 pkgsrc/devel/xulrunner/dist.mk cvs rdiff -u -r1.35 -r1.36 pkgsrc/devel/xulrunner/distinfo cvs rdiff -u -r1.15 -r1.16 pkgsrc/devel/xulrunner/mozilla-common.mk cvs rdiff -u -r1.1.1.1 -r1.2 pkgsrc/devel/xulrunner/patches/patch-ag \ pkgsrc/devel/xulrunner/patches/patch-al cvs rdiff -u -r1.3 -r1.4 pkgsrc/devel/xulrunner/patches/patch-ap cvs rdiff -u -r1.1 -r1.2 pkgsrc/devel/xulrunner/patches/patch-mc cvs rdiff -u -r1.2 -r1.3 pkgsrc/devel/xulrunner/patches/patch-mm \ pkgsrc/devel/xulrunner/patches/patch-mn
2010-07-27Pullup ticket #3189 - requested by tnntron2-6/+6
devel/xulrunner: security update www/firefox: security update Revisions pulled up: - devel/xulrunner/dist.mk 1.13 - devel/xulrunner/distinfo 1.35 --- Module Name: pkgsrc Committed By: tnn Date: Tue Jul 27 07:58:53 UTC 2010 Modified Files: pkgsrc/devel/xulrunner: dist.mk distinfo Log Message: Update to firefox-3.6.8. Fixes a heap corruption issue due to free() of garbage pointers when parsing an invalid <object> tag.
2010-07-22Pullup ticket #3177 - requested by tnntron5-34/+15
devel/xulrunner: security update www/firefox: security update Revisions pulled up: - devel/xulrunner/PLIST 1.23 - devel/xulrunner/dist.mk 1.12 - devel/xulrunner/distinfo 1.34 - devel/xulrunner/patches/patch-bc delete - devel/xulrunner/patches/patch-mp 1.4 --- Module Name: pkgsrc Committed By: tnn Date: Wed Jul 21 16:55:34 UTC 2010 Modified Files: pkgsrc/devel/xulrunner: PLIST dist.mk distinfo pkgsrc/devel/xulrunner/patches: patch-mp Removed Files: pkgsrc/devel/xulrunner/patches: patch-bc Log Message: firefox-3.6.7 / xulrunner-1.9.2.7 security update. MFSA 2010-47 Cross-origin data leakage from script filename in error messages MFSA 2010-46 Cross-domain data theft using CSS MFSA 2010-45 Multiple location bar spoofing vulnerabilities MFSA 2010-44 Characters mapped to U+FFFD in 8 bit encodings cause subsequent character to vanish MFSA 2010-43 Same-origin bypass using canvas context MFSA 2010-42 Cross-origin data disclosure via Web Workers and importScripts MFSA 2010-41 Remote code execution using malformed PNG image MFSA 2010-40 nsTreeSelection dangling pointer remote code execution MFSA 2010-39 nsCSSValue::Array index integer overflow MFSA 2010-38 Arbitrary code execution using SJOW and fast native function MFSA 2010-37 Plugin parameter EnsureCachedAttrParamArrays remote code execution MFSA 2010-36 Use-after-free error in NodeIterator MFSA 2010-35 DOM attribute cloning remote code execution vulnerability MFSA 2010-34 Miscellaneous memory safety hazards (rv:1.9.2.7/ 1.9.1.11)
2010-06-24Security update of firefox & xulrunner to 3.6.4 (1.9.1.2).tnn5-14/+18
MFSA 2010-33 User tracking across sites using Math.random() MFSA 2010-32 Content-Disposition: attachment ignored if Content-Type: multipart also present MFSA 2010-31 focus() behavior can be used to inject or steal keystrokes MFSA 2010-30 Integer Overflow in XSLT Node Sorting MFSA 2010-29 Heap buffer overflow in nsGenericDOMDataNode::SetTextInternal MFSA 2010-28 Freed object reuse across plugin instances MFSA 2010-26 Crashes with evidence of memory corruption
2010-06-13Bump PKGREVISION for libpng shlib name change.wiz1-2/+2
Also add some patches to remove use of deprecated symbols and fix other problems when looking for or compiling against libpng-1.4.x.
2010-04-28--disable-installer to make Linux builds of thunderbird happy.tnn1-1/+2
2010-04-26fix linux PLIST breakage in devel/nsstnn2-1/+15
2010-04-26fix linux PLIST issuestnn4-4/+22
2010-04-22common makefile fragment for mozilla extension packagestnn1-0/+24
2010-04-21Disable assembly routines in freebl on Linux.tnn2-5/+17
This works around the PR pkg/43146 crash, at least on debian 5.0/i386.
2010-04-02firefox-3.6.3 fixes a use-after-free bug which could be exploited totnn3-8/+7
run arbitrary code.
2010-04-01add support for NetBSD/mipsjmcneill7-12/+247
2010-03-30${LOWER_OPSYS} strikes again! (PR pkg/43080)tnn1-2/+2
2010-03-23Update to firefox-3.6.2 proper. (no changes from the beta)tnn4-11/+24
Also add patch for PR pkg/42988 crash, effectively disabling all sound support until we decide on what sound API to use. The current dlopen() guesswork is bad, mkay. Bump PKGREVISION for this and previous changes.
2010-03-17match-mb: make BSD/x86 targets use the same XPTCall code as Linux.tnn3-36/+44
patch-ab: NetBSD always has >4GB off_t, so use it.
2010-03-16Update to firefox-3.6.2.tnn24-4427/+3501
.2 is not formally released yet, but is release tagged in the scm and I want to get this update in before we freeze the tree. "Firefox 3.6 is built on Mozilla's Gecko 1.9.2 web rendering platform, which has been under development since early 2009 and contains many improvements for web developers, add-on developers, and users." - Improved JavaScript performance, overall browser responsiveness, and startup time. - The ability for web developers to indicate that scripts should run asynchronously to speed up page load times. - Continued support for downloadable web fonts using the new WOFF font format. - Support for new CSS attributes such as gradients, background sizing, and pointer events. - Support for new DOM and HTML5 specifications including the Drag & Drop API and the File API, which allow for more interactive web pages.
2010-03-16prepare common Makefile for firefox-3.6.2 update.tnn1-2/+7
2010-03-03bump the minimum sqlite dependency to what configure expectstnn1-2/+2
2010-02-17Update to firefox-3.5.8 and xulrunner-1.9.1.8.tnn3-9/+9
Security and bugfix release. (no MFSAs released at time of writing) While here drop defunct debug option from firefox and reduce diff to wip/
2010-01-31add some convenience variables for version handlingtnn2-5/+7
2010-01-26Update "firefox" package to 3.5.7. Changes since version 3.5.6:tron3-9/+7
- Fixed a common stability issue. - Fixed a problem with how updates were being presented to users. Approved by Tobias Nygren.
2010-01-21Bump PKGREVISION from jpeg shlib bump.obache1-1/+2
2010-01-19# used by devel/nss/Makefiletnn1-1/+2
2010-01-18unlimit datasize. Should fix ICE on netbsd-4/amd64 observed in bulk build.tnn1-1/+2
2010-01-18Second try at jpeg-8 recursive PKGREVISION bump.wiz1-2/+2
2010-01-16Added LICENSE.heinz1-1/+2
2010-01-10Fix build with Sun Sudio C++ by not including "stdbool.h" in C++ mode.tron2-1/+21
2010-01-09This package needs a C99 compiler (e.g. for "stdbool.h").tron1-2/+2
2010-01-09Use pkgsrc's libbz2.so on Solaris.tnn1-1/+6
The native one doesn't export BZ2_crc32Table for some reason.
2009-12-16Update to firefox-3.5.6. Security and bugfix release.tnn5-26/+26
While here, switch NetBSD build from sunaudio to OSS emulation. This greatly improves HTML5 video playback. (Yes, we ought to fix the busted sunaudio support or PKG_OPTIONalize this. Perhaps another day.) Advisories relating to this release: MFSA 2009-71 GeckoActiveXObject exception messages can be used to enumerate installed COM objects MFSA 2009-70 Privilege escalation via chrome window.opener MFSA 2009-69 Location bar spoofing vulnerabilities MFSA 2009-68 NTLM reflection vulnerability MFSA 2009-67 Integer overflow, crash in libtheora video library MFSA 2009-66 Memory safety fixes in liboggplay media library MFSA 2009-65 Crashes with evidence of memory corruption (rv:1.9.1.6/ 1.9.0.16)
2009-12-11drop patch-rb which changed the unofficial firefox branding in a way thattnn2-9/+1
made the firefox addons site not automagically recognize the browser.
2009-12-04add buildlinkry for libjpeg. We can end up linking with the wrong libjpegtnn1-1/+4
on Linux otherwise. There are still other problems with interference from native libraries (i.e. sqlite3).
2009-12-01fix patch commenttnn2-4/+4
2009-11-28fix typo in dependency patterntnn1-2/+2
2009-11-27bump the minimum required GTK+ to 2.18.3nb1tnn2-3/+4
2009-11-23add "used by" linestnn2-2/+8
2009-11-10bump revision for patch-{az,ba}tnn1-1/+2
2009-11-10integrate two patches from devel/nspr; avoid 32 bit cast of pthread_t.tnn3-1/+46
2009-11-06Update to firefox 3.5.5. This is a stability/bugfix update.tnn4-13/+26
pkgsrc changes: - assign devel/xulrunner maintainership to tnn@ - mozilla-common.mk: work around gcc __thread support misdetection on NetBSD - separate distinfo related stuff into dist.mk for sharing with nss & nspr "topcrash" bugs fixed: 468562 "ASSERTION: Inserting multiple children without flushing" 521750 Put a runtime NS_IsMainThread check in nsCycleCollector::Suspect2 ... 524462 startup crash [@ gfxWindowsFontGroup::WhichFontSupportsChar(nsTAr ... 525326 Crashes in gif decoder [@ xul.dll@0x348945][@ xul.dll@0x348864][@ ... 525276 crashes [@ nsDocument::RegisterNamedItems(nsIContent*)]
2009-11-04back out local changetnn1-5/+1
2009-11-04remove useless, ancient patch hunk which drifted away from it's originaltnn2-23/+7
location during the course of time ...
2009-11-04apply band-aid for nbsed bug.tnn3-7/+21
2009-11-03The minimum required sqlite3 version changed (again ... grumble.)tnn2-3/+4
reported by Snader_LB @ #pkgsrc
2009-10-28Security and bugfix update of firefox (to 3.5.4) and xulrunner (to 1.9.1.4)tnn10-91/+37
Also fix broken DESTDIR support. Fixes the following security issues: MFSA 2009-64 Crashes with evidence of memory corruption (rv:1.9.1.4/ 1.9.0.15) MFSA 2009-63 Upgrade media libraries to fix memory safety bugs MFSA 2009-62 Download filename spoofing with RTL override MFSA 2009-61 Cross-origin data theft through document.getSelection() MFSA 2009-59 Heap buffer overflow in string to number conversion MFSA 2009-57 Chrome privilege escalation in XPCVariant::VariantDataToJS() MFSA 2009-56 Heap buffer overflow in GIF color map parser MFSA 2009-55 Crash in proxy auto-configuration regexp parsing MFSA 2009-54 Crash with recursive web-worker calls MFSA 2009-53 Local downloaded file tampering MFSA 2009-52 Form history vulnerable to stealing
2009-10-11- allow firefox and xulrunner to share some infrastructuretnn8-76/+156
- install headers for plugin and liveconnect (needed by openjdk7-icedtea-plugin) - bump revision for both packages
2009-10-10add common Makefile fragment for mozilla packages based on gecko 1.9.1,tnn1-0/+66
such as xulrunner-1.9.1, firefox-3.5, thunderbird-3.0 and seamonkey-2.0. Nothing in the tree uses this file yet. Having it here now makes for one less pullup later.
2009-10-06remove three files which were listed twice in the PLISTtnn1-4/+1
2009-09-27The xulrunner distfile is just a copy of the firefox distfile.tnn2-9/+9
Let's use the latter directly instead to save bandwidth and allow faster security updates.
2009-09-20modify patches to work on FreeBSD, toosno4-13/+19
2009-09-20better version of patch-ax, from veego@tnn2-10/+10