Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 08 Sep 2016 22:41:17 +0000
From:      bugzilla-noreply@freebsd.org
To:        gecko@FreeBSD.org
Subject:   [Bug 212463] mail/thunderbird: update to 45.3.0
Message-ID:  <bug-212463-21738-2j4ct7urAr@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-212463-21738@https.bugs.freebsd.org/bugzilla/>
References:  <bug-212463-21738@https.bugs.freebsd.org/bugzilla/>

next in thread | previous in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D212463

Jan Beich <jbeich@FreeBSD.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
 Attachment #174541|                            |maintainer-approval+
              Flags|                            |

--- Comment #8 from Jan Beich <jbeich@FreeBSD.org> ---
Comment on attachment 174541
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=3D174541
vuln.xml fragment for mozilla 48/45.3esr

Looks good enough to land but some things can be improved.

>	<blockquote cite=3D"https://www.mozilla.org/en-US/security/known-vulnerab=
ilities/firefox-esr/#firefoxesr45.3">

This one lacks MFSA 2016-{66,68,69,71,74,75,81..84} better cite one of the
following:

https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox/#firef=
ox48
https://www.mozilla.org/en-US/security/advisories/

>    <dates>
>      <discovery>2016-08-30</discovery>

According to the cited page and "Announced" field within those MFSAs it sho=
uld
be 2016-08-02. Have I missed something?

(In reply to Christoph Moench-Tegeder from comment #6)
>>>  <vuln vid=3D"aa1aefe3-6e37-47db-bfda-343ef4acb1b5">
>> Unless you want to keep this specific to MFSA 2016-62 use same VID as in=
 ports > r419401.
> If it did exist...

Apologies, I did reserve VID (ahead of the announcement) but haven't found =
time
to fill it in. The intent was to warn users about security impact regardles=
s of
VuXML.

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-212463-21738-2j4ct7urAr>