Bug#561750: icedove: embeds xulrunner

Mike Hommey mh at glandium.org
Sun Dec 20 08:42:29 GMT 2009


forwarded 561750 https://bugzilla.mozilla.org/show_bug.cgi?id=306324
tag 561750 + upstream
thanks

On Sat, Dec 19, 2009 at 10:46:31PM -0500, Michael Gilbert wrote:
> package: icedove
> version: 3.0~rc2
> severity: important
> tags: security
> 
> Hi,
> 
> Your package embeds source code from xulrunner, which makes
> security updates very cumbersome, difficult, and potentially
> error-prone.  Please update your package to make use of the
> shared library.  Thank you for your attention on this matter.

This is known, and not possible (yet). Likewise for iceape.

The main difference with the situation in lenny is that the mozilla/
directory in iceape and icedove 3 sources are the same as the
xulrunner-1.9.1 source, which will make updates easier.

This is the main reason why I'm seriously considering shipping iceweasel
3.5.x with squeeze instead of 3.6.x.

Mike





More information about the Ubuntu-mozillateam mailing list