[ubuntu/cosmic-proposed] mozjs52 52.8.1-0ubuntu1 (Accepted)

Chris Coulson chris.coulson at canonical.com
Tue Jun 19 14:40:19 UTC 2018


mozjs52 (52.8.1-0ubuntu1) cosmic; urgency=medium

  * SECURITY UPDATE: Multiple memory safety issues
    - CVE-2017-7810, CVE-2017-7826, CVE-2018-5089, CVE-2018-5125,
      CVE-2018-5150

  * Update to 52.8.1esr
  * Drop patches that are fixed upstream
    - remove debian/patches/remove-nspr-dependency.patch
    - remove debian/patches/tests-skip-on-all-64-bit-archs.patch
    - update debian/patches/series
  * Refresh patches
    - update debian/patches/include-configure-script.patch - the
      configure script is included in the tarball now. This patch should
      probably be renamed to something more appropriate
    - update debian/patches/pre-generate-old-configure.patch - a pre-generated
      old-configure script is included in the tarball now, although the one
      generated by js/src/make-source-package.sh includes the wrong aclocal.m4
      and doesn't work, so regenerate it again with the correct aclocal.m4
  * Move pre-generate-old-configure.patch to after
    Allow-to-override-ICU_DATA_FILE-from-the-environment.patch and drop
    Patch-pregenerated-old-configure-to-match-build-autoconf-.patch
    - update debian/patches/series
    - remove debian/patches/Patch-pregenerated-old-configure-to-match-build-autoconf-.patch
    - update debian/patches/pre-generate-old-configure.patch to refresh old-configure
  * Don't build-depend on libicu-dev - the bundled ICU is used and the
    distro ICU package ships the layout engine API since 60.2, which
    causes intl/icu_sources_data.py to fail due to source files excluded from
    the Mozilla source

Date: Mon, 11 Jun 2018 18:00:08 +0100
Changed-By: Chris Coulson <chris.coulson at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/mozjs52/52.8.1-0ubuntu1
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 11 Jun 2018 18:00:08 +0100
Source: mozjs52
Binary: libmozjs-52-0 libmozjs-52-dev
Architecture: source
Version: 52.8.1-0ubuntu1
Distribution: cosmic
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Chris Coulson <chris.coulson at canonical.com>
Description:
 libmozjs-52-0 - SpiderMonkey JavaScript library
 libmozjs-52-dev - SpiderMonkey JavaScript library - development headers
Changes:
 mozjs52 (52.8.1-0ubuntu1) cosmic; urgency=medium
 .
   * SECURITY UPDATE: Multiple memory safety issues
     - CVE-2017-7810, CVE-2017-7826, CVE-2018-5089, CVE-2018-5125,
       CVE-2018-5150
 .
   * Update to 52.8.1esr
   * Drop patches that are fixed upstream
     - remove debian/patches/remove-nspr-dependency.patch
     - remove debian/patches/tests-skip-on-all-64-bit-archs.patch
     - update debian/patches/series
   * Refresh patches
     - update debian/patches/include-configure-script.patch - the
       configure script is included in the tarball now. This patch should
       probably be renamed to something more appropriate
     - update debian/patches/pre-generate-old-configure.patch - a pre-generated
       old-configure script is included in the tarball now, although the one
       generated by js/src/make-source-package.sh includes the wrong aclocal.m4
       and doesn't work, so regenerate it again with the correct aclocal.m4
   * Move pre-generate-old-configure.patch to after
     Allow-to-override-ICU_DATA_FILE-from-the-environment.patch and drop
     Patch-pregenerated-old-configure-to-match-build-autoconf-.patch
     - update debian/patches/series
     - remove debian/patches/Patch-pregenerated-old-configure-to-match-build-autoconf-.patch
     - update debian/patches/pre-generate-old-configure.patch to refresh old-configure
   * Don't build-depend on libicu-dev - the bundled ICU is used and the
     distro ICU package ships the layout engine API since 60.2, which
     causes intl/icu_sources_data.py to fail due to source files excluded from
     the Mozilla source
Checksums-Sha1:
 12c8b4ae455003b336b31a2b6e55b26e1ebb8f78 2018 mozjs52_52.8.1-0ubuntu1.dsc
 ff7de34d81fcc44bc73965a6fdf8c07a103b0cc3 30270011 mozjs52_52.8.1.orig.tar.bz2
 4ddf1fd6e58dc50fe2212aa40306d288985c7dcd 27964 mozjs52_52.8.1-0ubuntu1.debian.tar.xz
 9a229a6d4b9f1f2885c9b7cc8ad0896d0d0ab717 11335 mozjs52_52.8.1-0ubuntu1_source.buildinfo
Checksums-Sha256:
 70947da38b80e066c9c01224c998a23a5e9cc1f7855b5d99b852e437f1901ac8 2018 mozjs52_52.8.1-0ubuntu1.dsc
 fb5e11b7f31a33be820d5c947c5fa114751b0d5033778c1cd8e0cf2dad91e8fa 30270011 mozjs52_52.8.1.orig.tar.bz2
 f5733225f0548688b3075ea7443e6c38180bcf411cb45108bcb1201f83b252b1 27964 mozjs52_52.8.1-0ubuntu1.debian.tar.xz
 bfbc512bcec81cb95283eb84c33cee9de41dc979727e91a3eb6387222b9fcbc3 11335 mozjs52_52.8.1-0ubuntu1_source.buildinfo
Files:
 5fe50fde27b5912cd59587635b5d8030 2018 libs optional mozjs52_52.8.1-0ubuntu1.dsc
 3a44c2fd3d7b5a370ed9184163c74bc4 30270011 libs optional mozjs52_52.8.1.orig.tar.bz2
 459eef824919785bba894ba8717dcd2c 27964 libs optional mozjs52_52.8.1-0ubuntu1.debian.tar.xz
 299f09b673ee6a4237997568b983e1d3 11335 libs optional mozjs52_52.8.1-0ubuntu1_source.buildinfo
Original-Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers at lists.alioth.debian.org>

-----BEGIN PGP SIGNATURE-----

iQFQBAEBCgA6FiEERN//5MGgCOgyKeIFYR+97NWUbg8FAlshlEscHGNocmlzLmNv
dWxzb25AY2Fub25pY2FsLmNvbQAKCRBhH73s1ZRuD3m8CACh1lT/0NaKFodkusmW
ZkXh1d1E1YHzX875dt9tHhbSpdaLCEv0iwswF/82ZS8M/8s4M4FK6JEUKoas/Utj
X4uxy7nU/67icz5KjrChvAg3tZLmwy1XI5LHjJeLVUvfd5B3pouCRgG06+gpgiYW
C7SzEdOgfw7uCTRbQdurSMveWmT7dTe/gdHWP5uejvs9Y+s0yeaYeCozxxA1oiWo
okLE7FMy8jVpn+U+2Zj2Lx01034xeJa+WGAoi0f6soLjE0Jnx0esAX0cgNYKmAsQ
crco2UEe6CZN2qCgydSogq0x5FMUUbNopLJy6RnJmB9puH0U5QUCkcSIuYWFsS1g
gyFG
=VWX/
-----END PGP SIGNATURE-----


More information about the Cosmic-changes mailing list