From owner-freebsd-gnome Fri Jul 12 2:20: 0 2002 Delivered-To: freebsd-gnome@freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D4F6637B400; Fri, 12 Jul 2002 02:19:58 -0700 (PDT) Received: from blues.jpj.net (blues.jpj.net [208.210.80.156]) by mx1.FreeBSD.org (Postfix) with ESMTP id 2B77B43E5E; Fri, 12 Jul 2002 02:19:58 -0700 (PDT) (envelope-from trevor@jpj.net) Received: from blues.jpj.net (localhost.jpj.net [127.0.0.1]) by blues.jpj.net (8.12.3/8.12.3) with ESMTP id g6C9Jvp7001144; Fri, 12 Jul 2002 05:19:57 -0400 (EDT) (envelope-from trevor@jpj.net) Received: from localhost (trevor@localhost) by blues.jpj.net (8.12.3/8.12.3/Submit) with ESMTP id g6C9Juw3001141; Fri, 12 Jul 2002 05:19:56 -0400 (EDT) X-Authentication-Warning: blues.jpj.net: trevor owned process doing -bs Date: Fri, 12 Jul 2002 05:19:56 -0400 (EDT) From: Trevor Johnson To: gnome@freebsd.org Cc: security-team@freebsd.org Subject: Re: remote DoS in Mozilla 1.0 In-Reply-To: <20020613180046.A9558@lemuria.org> Message-ID: <20020712050851.M359-100000@blues.jpj.net> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-gnome@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG I have confirmed that this bug exists in the mozilla-1.0,1 package from ports/www/mozilla/. A patch is available, which I have readied for use in the port. I have confirmed thatp the patched Mozilla does not have the bug. Please incorporate the patch from http://people.freebsd.org/~trevor/ports/mozilla-hugefonts.diff into the port. For more information on the bug, see http://web.lemuria.org/security/mozilla-dos.html or Bugzilla . -- Trevor Johnson To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-gnome" in the body of the message